{"id":"CVE-2026-18678","aliases":["GHSA-v95x-xhq5-4929","CVE-2026-50166","GO-2026-6010"],"title":"kumactl connects to control plane without verifying TLS certificate when no CA is configured","summary":"kumactl connects to control plane without verifying TLS certificate when no CA is configured","severity":"medium","vendor":"kumahq","product":"github.com/kumahq/kuma/v2","ecosystem":"go","affected":["github.com/kumahq/kuma/v2 < 2.7.26","github.com/kumahq/kuma/v2 >= 2.8.0, < 2.9.16","github.com/kumahq/kuma/v2 >= 2.10.0, < 2.11.14","github.com/kumahq/kuma/v2 >= 2.12.0, < 2.12.11","github.com/kumahq/kuma/v2 >= 2.13.0, < 2.13.7","github.com/kumahq/kuma <= 1.8.1"],"patched":["github.com/kumahq/kuma/v2 2.7.26","github.com/kumahq/kuma/v2 2.9.16","github.com/kumahq/kuma/v2 2.11.14","github.com/kumahq/kuma/v2 2.12.11","github.com/kumahq/kuma/v2 2.13.7"],"published":"2026-07-16","updated":"2026-08-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v95x-xhq5-4929","references":[{"url":"https://github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929"},{"url":"https://github.com/kumahq/kuma/pull/16777"},{"url":"https://github.com/kumahq/kuma/commit/2ecadac1aa2fd8cded4c2ab768949f4c2ec83e2a"},{"url":"https://github.com/kumahq/kuma"}],"tags":["osv","go"],"epss":0.00096,"epssPercentile":0.0081,"ingestedAt":"2026-08-13T19:18:21.341Z","slug":"CVE-2026-18678","body":"## Overview\n\nWhen an operator adds an HTTPS control plane profile to `kumactl` without providing a CA certificate, `kumactl` disables TLS verification and sends API tokens over the unverified connection\n\n## Impact\n\nAn attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user\n\n## Affected configurations\n\n- `kumactl` profiles manually added against an HTTPS control plane endpoint without `--ca-cert-file`\n\n## Not affected\n\n- The default local profile, which uses plain HTTP\n\n## Workarounds\n\nWhen adding an HTTPS control plane profile to `kumactl`, always pass `--ca-cert-file` pointing at the control plane's serving CA. Alternatively, terminate the control plane behind a publicly trusted certificate; the patched releases will verify successfully against the operating system trust store with no further configuration\n\n## Resources\n\n- Fix: https://github.com/kumahq/kuma/pull/16777\n\n## Affected packages\n\n- `github.com/kumahq/kuma/v2 < 2.7.26`\n- `github.com/kumahq/kuma/v2 >= 2.8.0, < 2.9.16`\n- `github.com/kumahq/kuma/v2 >= 2.10.0, < 2.11.14`\n- `github.com/kumahq/kuma/v2 >= 2.12.0, < 2.12.11`\n- `github.com/kumahq/kuma/v2 >= 2.13.0, < 2.13.7`\n- `github.com/kumahq/kuma <= 1.8.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/kumahq/kuma/v2 2.7.26`\n- `github.com/kumahq/kuma/v2 2.9.16`\n- `github.com/kumahq/kuma/v2 2.11.14`\n- `github.com/kumahq/kuma/v2 2.12.11`\n- `github.com/kumahq/kuma/v2 2.13.7`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}