CVE-2026-18678
Published:August 12, 2026
Updated:September 01, 2026
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.
An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
Affected Packages
https://github.com/kumahq/kuma.git (GITHUB):
Affected version(s) >=v2.11.8 <v2.11.14Fix Suggestion:
Update to version v2.11.14https://github.com/kumahq/kuma.git (GITHUB):
Affected version(s) >=v2.12.4 <v2.12.11Fix Suggestion:
Update to version v2.12.11https://github.com/kumahq/kuma.git (GITHUB):
Affected version(s) >=v2.7.20 <v2.7.26Fix Suggestion:
Update to version v2.7.26https://github.com/kumahq/kuma.git (GITHUB):
Affected version(s) >=v2.13.0 <v2.13.7Fix Suggestion:
Update to version v2.13.7Related Resources (7)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.5
Attack Vector
ADJACENT
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
HIGH
Subsequent System Availability
HIGH
CVSS v3
Base Score:
7.9
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
Improper Certificate Validation
EPSS
Base Score:
0.10