Description
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
Published: 2026-09-15
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unverified TLS connection allows an on‑path attacker to intercept the dataplane authentication token, impersonate the control plane, and inject a forged bootstrap configuration leading to proxy takeover
Action: Immediate Patch
AI Analysis

Impact

Prior to the released fixes, Kuma Universal mode dataplanes that were started without a CA certificate or without setting the KUMA_CONTROL_PLANE_CA_CERT environment variable would connect to an HTTPS control plane without performing TLS peer verification. The dataplane therefore sends its authentication token over an unverified connection. An attacker following the traffic could capture this token, impersonate the control plane, and inject a forged bootstrap configuration, effectively taking over the proxy. Standard Kubernetes installations created with kumactl install control‑plane or the official Helm chart are not affected because the admission webhook injects the control‑plane CA certificate into each sidecar, enforcing TLS verification.

Affected Systems

Affected products are Kuma v2.7.x, 2.9.x, 2.11.x, 2.12.x, and 2.13.x versions earlier than 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7 respectively. Standard Kubernetes installations created by kumactl install control‑plane or the official Helm chart are not impacted because the admission webhook automatically injects the control‑plane CA certificate into each sidecar, ensuring TLS verification is performed.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, so there is no evidence yet of widespread exploitation. An attacker only needs to intercept traffic to a dataplane that is not enforcing TLS verification, which can be feasible in shared or compromised network environments. Thus, the exploit remains attainable whenever the dataplane omits a CA certificate and the network path is vulnerable.

Generated by OpenCVE AI on September 20, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kuma to any patched release (v2.7.26, v2.9.16, v2.11.14, v2.12.11, v2.13.7 or later) to apply the fix for this TLS verification issue
  • If using Kubernetes, install Kuma via kumactl install control‑plane or the official Helm chart so that the admission webhook injects the control‑plane CA certificate, guaranteeing TLS verification
  • For non‑Kubernetes or manually configured deployments, set the control‑plane CA certificate explicitly using the --ca-cert-file option or the KUMA_CONTROL_PLANE_CA_CERT environment variable so that TLS peer verification is performed in all dataplane connections

Generated by OpenCVE AI on September 20, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wvmp-6r4v-j6cv kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
History

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Kumahq
Kumahq kuma
Vendors & Products Kumahq
Kumahq kuma

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
Title kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:21:20.402Z

Reserved: 2026-06-08T14:00:43.571Z

Link: CVE-2026-52724

cve-icon Vulnrichment

Updated: 2026-09-15T15:20:34.771Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:17.110

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-52724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses
  • CWE-295

    Improper Certificate Validation