Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v95x-xhq5-4929 | kumactl connects to control plane without verifying TLS certificate when no CA is configured |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kumahq
Kumahq kuma |
|
| Vendors & Products |
Kumahq
Kumahq kuma |
Tue, 15 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. | |
| Title | Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-16T15:50:24.712Z
Reserved: 2026-06-03T20:54:20.433Z
Link: CVE-2026-50166
Updated: 2026-09-16T15:50:17.569Z
Status : Received
Published: 2026-09-15T15:17:16.950
Modified: 2026-09-16T16:17:08.247
Link: CVE-2026-50166
No data.
OpenCVE Enrichment
Updated: 2026-09-16T03:45:08Z
Github GHSA