CVE-2026-50166: CWE-295: Improper Certificate Validation in kumahq kuma
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
AI Analysis
Technical Summary
Kuma, an Envoy-based service mesh, suffers from CWE-295 (Improper Certificate Validation) in versions prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. When a kumactl profile is manually configured for HTTPS control plane access without the --ca-cert-file option, TLS peer verification is disabled. This results in API tokens being transmitted over an unverified connection, enabling a man-in-the-middle attacker to intercept these tokens and impersonate users or administrators against the control plane. The default local profile is unaffected since it uses plain HTTP. The vulnerability has been addressed in the listed fixed versions.
Potential Impact
An attacker positioned on the network path can intercept API tokens sent over an unverified TLS connection due to disabled peer verification. This allows the attacker to impersonate users or administrators and perform unauthorized actions against the Kuma control plane. The default local profile is not impacted. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Kuma to versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7 or later where this issue is fixed. Avoid manually configuring kumactl profiles for HTTPS control planes without specifying the --ca-cert-file option to ensure TLS peer verification is enabled. Since this is a software vulnerability, patching to the fixed versions is the recommended remediation.
CVE-2026-50166: CWE-295: Improper Certificate Validation in kumahq kuma
Description
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
CVSS v4.0
Score 5.5medium
Affected software
kumahq
kuma
pkg:github/kumahq/kumaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kuma, an Envoy-based service mesh, suffers from CWE-295 (Improper Certificate Validation) in versions prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. When a kumactl profile is manually configured for HTTPS control plane access without the --ca-cert-file option, TLS peer verification is disabled. This results in API tokens being transmitted over an unverified connection, enabling a man-in-the-middle attacker to intercept these tokens and impersonate users or administrators against the control plane. The default local profile is unaffected since it uses plain HTTP. The vulnerability has been addressed in the listed fixed versions.
Potential Impact
An attacker positioned on the network path can intercept API tokens sent over an unverified TLS connection due to disabled peer verification. This allows the attacker to impersonate users or administrators and perform unauthorized actions against the Kuma control plane. The default local profile is not impacted. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Kuma to versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7 or later where this issue is fixed. Avoid manually configuring kumactl profiles for HTTPS control planes without specifying the --ca-cert-file option to ensure TLS peer verification is enabled. Since this is a software vulnerability, patching to the fixed versions is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T20:54:20.433Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa95dfa55bf5e2cf5f98f4f
Added to database: 09/15/2026, 15:02:18 UTC
Last enriched: 09/15/2026, 15:17:13 UTC
Last updated: 09/15/2026, 22:11:32 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.