MEDIUM 5.5 NVD

CVE-2026-18678

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.

References

Published: 2026-08-12 · Source: NVD · Feed updated: 2026-08-12
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.