Skip to main content

CVE-2026-52724: CWE-295: Improper Certificate Validation in kumahq kuma

0
Medium
VulnerabilityCVE-2026-52724cvecve-2026-52724cwe-295
Published: 09/15/2026 (09/15/2026, 14:50:32 UTC)
Source: CVE Database V5
Vendor/Project: kumahq
Product: kuma

Description

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.

CVSS v4.0

Score 5.8medium

Attack Vector
Adjacent Network
Attack Complexity
High
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Affected software

kumahq

kuma

Affected versions
<2.7.26>=2.8.0 <2.9.16>=2.10.0 <2.11.14>=2.12.0 <2.12.11>=2.13.0 <2.13.7
GitHub Actionsmore threats →ai
kumahq/kuma
pkg:github/kumahq/kuma
Affected versions
<2.7.26>=2.8.0 <2.9.16>=2.10.0 <2.11.14>=2.12.0 <2.12.11>=2.13.0 <2.13.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 15:17:07 UTC

Technical Analysis

Kuma, an Envoy-based service mesh, suffers from CWE-295: Improper Certificate Validation in Universal mode prior to versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. Specifically, if the --ca-cert-file flag is not supplied and the KUMA_CONTROL_PLANE_CA_CERT environment variable is unset, TLS peer verification is disabled for kuma-dp connections to an HTTPS control plane. This allows an on-path attacker to intercept the dataplane authentication token, impersonate the control plane, inject forged bootstrap configurations, and take control of the proxy. Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because they inject the necessary certificate environment variable via a mutating admission webhook. The vulnerability is addressed in the listed fixed versions.

Potential Impact

An attacker positioned on the network path can intercept the dataplane authentication token due to disabled TLS peer verification, enabling impersonation of the control plane. This can lead to injection of forged configurations and full takeover of the proxy component. However, standard Kubernetes deployments using official installation methods are not vulnerable. The CVSS 4.0 base score is 5.8 (medium severity), reflecting the complexity and attack vector.

Mitigation Recommendations

Upgrade to Kuma versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7 or later, where this issue is fixed. For deployments not using the standard Kubernetes installation methods, ensure that TLS peer verification is enabled by supplying the --ca-cert-file flag or setting the KUMA_CONTROL_PLANE_CA_CERT environment variable. Standard Kubernetes installations using kumactl install control-plane or the official Helm chart are not affected and require no additional action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-08T14:00:43.571Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa95dfa55bf5e2cf5f98f50

Added to database: 09/15/2026, 15:02:18 UTC

Last enriched: 09/15/2026, 15:17:07 UTC

Last updated: 09/15/2026, 22:25:41 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses