CVE-2026-50166
Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
| CWE | CWE-295 |
| Vendor | kumahq |
| Product | kuma |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for kumahq kuma
Be the first to know when new unknown vulnerabilities affecting kumahq kuma are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
kumahq / kuma
< 2.7.26
References
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929 github.com: https://github.com/kumahq/kuma/pull/16777 github.com: https://github.com/kumahq/kuma/commit/2d0fb382924598f8746bc85c896f50384675940f github.com: https://github.com/kumahq/kuma/commit/85716397ffa404234bf365da0967eca0b0fa1870 github.com: https://github.com/kumahq/kuma/commit/a256af4869ae7e0ebbc2a14dc231e04ac8df1ba3 github.com: https://github.com/kumahq/kuma/commit/bb56ae628753aaec1f7846a514ab4edc35c0b569 github.com: https://github.com/kumahq/kuma/commit/d4ae0c0151596be991897651f20c5cdf32de1980 github.com: https://github.com/kumahq/kuma/commit/eb81494c2c7a5536e55c19cdde51b02a03b51e11