Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v95x-xhq5-4929 | kumactl connects to control plane without verifying TLS certificate when no CA is configured |
Tue, 15 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. | |
| Title | Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T14:52:30.085Z
Reserved: 2026-06-03T20:54:20.433Z
Link: CVE-2026-50166
No data.
Status : Received
Published: 2026-09-15T15:17:16.950
Modified: 2026-09-15T15:17:16.950
Link: CVE-2026-50166
No data.
OpenCVE Enrichment
No data.
-
CWE-295
Improper Certificate Validation
Github GHSA