VYPR
Medium severityNVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026

CVE-2026-52724

CVE-2026-52724

Description

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/kumahq/kuma/v2Go
< 2.7.262.7.26
github.com/kumahq/kuma/v2Go
>= 2.8.0, < 2.9.162.9.16
github.com/kumahq/kuma/v2Go
>= 2.10.0, < 2.11.142.11.14
github.com/kumahq/kuma/v2Go
>= 2.12.0, < 2.12.112.12.11
github.com/kumahq/kuma/v2Go
>= 2.13.0, < 2.13.72.13.7
github.com/kumahq/kumaGo
<= 1.8.1

Affected products

2

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.