CVE-2026-52724: CWE-295: Improper Certificate Validation in kumahq kuma
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
AI Analysis
Technical Summary
Kuma, an Envoy-based service mesh, suffers from CWE-295: Improper Certificate Validation in Universal mode prior to versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. Specifically, if the --ca-cert-file flag is not supplied and the KUMA_CONTROL_PLANE_CA_CERT environment variable is unset, TLS peer verification is disabled for kuma-dp connections to an HTTPS control plane. This allows an on-path attacker to intercept the dataplane authentication token, impersonate the control plane, inject forged bootstrap configurations, and take control of the proxy. Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because they inject the necessary certificate environment variable via a mutating admission webhook. The vulnerability is addressed in the listed fixed versions.
Potential Impact
An attacker positioned on the network path can intercept the dataplane authentication token due to disabled TLS peer verification, enabling impersonation of the control plane. This can lead to injection of forged configurations and full takeover of the proxy component. However, standard Kubernetes deployments using official installation methods are not vulnerable. The CVSS 4.0 base score is 5.8 (medium severity), reflecting the complexity and attack vector.
Mitigation Recommendations
Upgrade to Kuma versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7 or later, where this issue is fixed. For deployments not using the standard Kubernetes installation methods, ensure that TLS peer verification is enabled by supplying the --ca-cert-file flag or setting the KUMA_CONTROL_PLANE_CA_CERT environment variable. Standard Kubernetes installations using kumactl install control-plane or the official Helm chart are not affected and require no additional action.
CVE-2026-52724: CWE-295: Improper Certificate Validation in kumahq kuma
Description
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
CVSS v4.0
Score 5.8medium
Affected software
kumahq
kuma
pkg:github/kumahq/kumaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kuma, an Envoy-based service mesh, suffers from CWE-295: Improper Certificate Validation in Universal mode prior to versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. Specifically, if the --ca-cert-file flag is not supplied and the KUMA_CONTROL_PLANE_CA_CERT environment variable is unset, TLS peer verification is disabled for kuma-dp connections to an HTTPS control plane. This allows an on-path attacker to intercept the dataplane authentication token, impersonate the control plane, inject forged bootstrap configurations, and take control of the proxy. Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because they inject the necessary certificate environment variable via a mutating admission webhook. The vulnerability is addressed in the listed fixed versions.
Potential Impact
An attacker positioned on the network path can intercept the dataplane authentication token due to disabled TLS peer verification, enabling impersonation of the control plane. This can lead to injection of forged configurations and full takeover of the proxy component. However, standard Kubernetes deployments using official installation methods are not vulnerable. The CVSS 4.0 base score is 5.8 (medium severity), reflecting the complexity and attack vector.
Mitigation Recommendations
Upgrade to Kuma versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, or 2.13.7 or later, where this issue is fixed. For deployments not using the standard Kubernetes installation methods, ensure that TLS peer verification is enabled by supplying the --ca-cert-file flag or setting the KUMA_CONTROL_PLANE_CA_CERT environment variable. Standard Kubernetes installations using kumactl install control-plane or the official Helm chart are not affected and require no additional action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-08T14:00:43.571Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa95dfa55bf5e2cf5f98f50
Added to database: 09/15/2026, 15:02:18 UTC
Last enriched: 09/15/2026, 15:17:07 UTC
Last updated: 09/15/2026, 22:25:41 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.