Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured
Summary
| CVE | CVE-2026-50166 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-15 15:17:16 UTC |
| Updated | 2026-09-30 17:43:24 UTC |
| Description | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. |
Risk And Classification
Primary CVSS: v4.0 5.5 MEDIUM from [email protected]
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002750000 probability, percentile 0.180280000 (date 2026-10-02)
Problem Types: CWE-295 | CWE-295 CWE-295: Improper Certificate Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | DECLARED | 5.5 | MEDIUM | CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
HighAttack Requirements
PresentPrivileges Required
NoneUser Interaction
PassiveConfidentiality
NoneIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/kumahq/kuma/commit/bb56ae628753aaec1f7846a514ab4edc35c0b569 | [email protected] | github.com | |
| github.com/kumahq/kuma/commit/d4ae0c0151596be991897651f20c5cdf32de1980 | [email protected] | github.com | |
| github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929 | [email protected] | github.com | |
| github.com/kumahq/kuma/commit/2d0fb382924598f8746bc85c896f50384675940f | [email protected] | github.com | |
| github.com/kumahq/kuma/commit/85716397ffa404234bf365da0967eca0b0fa1870 | [email protected] | github.com | |
| github.com/kumahq/kuma/commit/a256af4869ae7e0ebbc2a14dc231e04ac8df1ba3 | [email protected] | github.com | |
| github.com/kumahq/kuma/commit/eb81494c2c7a5536e55c19cdde51b02a03b51e11 | [email protected] | github.com | |
| github.com/kumahq/kuma/pull/16777 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.