๐Ÿ” CVE Alert

CVE-2026-50166

UNKNOWN 0.0

Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.

CWE CWE-295
Vendor kumahq
Product kuma
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kumahq kuma

Be the first to know when new unknown vulnerabilities affecting kumahq kuma are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kumahq / kuma
< 2.7.26

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929 github.com: https://github.com/kumahq/kuma/pull/16777 github.com: https://github.com/kumahq/kuma/commit/2d0fb382924598f8746bc85c896f50384675940f github.com: https://github.com/kumahq/kuma/commit/85716397ffa404234bf365da0967eca0b0fa1870 github.com: https://github.com/kumahq/kuma/commit/a256af4869ae7e0ebbc2a14dc231e04ac8df1ba3 github.com: https://github.com/kumahq/kuma/commit/bb56ae628753aaec1f7846a514ab4edc35c0b569 github.com: https://github.com/kumahq/kuma/commit/d4ae0c0151596be991897651f20c5cdf32de1980 github.com: https://github.com/kumahq/kuma/commit/eb81494c2c7a5536e55c19cdde51b02a03b51e11