CVE-2026-50166
Description
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified connection. An attacker on the network path can intercept user or administrator API tokens and act against the control plane as the compromised user. The default local profile is unaffected because it uses plain HTTP. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kumahq/kuma/v2Go | < 2.7.26 | 2.7.26 |
github.com/kumahq/kuma/v2Go | >= 2.8.0, < 2.9.16 | 2.9.16 |
github.com/kumahq/kuma/v2Go | >= 2.10.0, < 2.11.14 | 2.11.14 |
github.com/kumahq/kuma/v2Go | >= 2.12.0, < 2.12.11 | 2.12.11 |
github.com/kumahq/kuma/v2Go | >= 2.13.0, < 2.13.7 | 2.13.7 |
github.com/kumahq/kumaGo | <= 1.8.1 | — |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-v95x-xhq5-4929ghsaADVISORY
- github.com/kumahq/kuma/commit/2ecadac1aa2fd8cded4c2ab768949f4c2ec83e2aghsaWEB
- github.com/kumahq/kuma/pull/16777nvdWEB
- github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929nvdWEB
- github.com/kumahq/kuma/commit/2d0fb382924598f8746bc85c896f50384675940fnvd
- github.com/kumahq/kuma/commit/85716397ffa404234bf365da0967eca0b0fa1870nvd
- github.com/kumahq/kuma/commit/a256af4869ae7e0ebbc2a14dc231e04ac8df1ba3nvd
- github.com/kumahq/kuma/commit/bb56ae628753aaec1f7846a514ab4edc35c0b569nvd
- github.com/kumahq/kuma/commit/d4ae0c0151596be991897651f20c5cdf32de1980nvd
- github.com/kumahq/kuma/commit/eb81494c2c7a5536e55c19cdde51b02a03b51e11nvd
News mentions
0No linked articles in our index yet.