MEDIUM 5.5 NVD
CVE-2026-18678
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.
An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
References
- https://developer.konghq.com/mesh/changelog/
- https://github.com/kumahq/kuma/pull/16777
- https://github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.