| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wvmp-6r4v-j6cv | kuma-dp connects to control plane without verifying TLS certificate when no CA is configured |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kumahq
Kumahq kuma |
|
| Vendors & Products |
Kumahq
Kumahq kuma |
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. | |
| Title | kuma-dp connects to control plane without verifying TLS certificate when no CA is configured | |
| Weaknesses | CWE-295 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T15:21:20.402Z
Reserved: 2026-06-08T14:00:43.571Z
Link: CVE-2026-52724
Updated: 2026-09-15T15:20:34.771Z
Status : Received
Published: 2026-09-15T15:17:17.110
Modified: 2026-09-15T16:17:12.540
Link: CVE-2026-52724
No data.
OpenCVE Enrichment
Updated: 2026-09-15T16:30:11Z
Github GHSA