{"id":"CVE-2026-18679","aliases":["GHSA-wvmp-6r4v-j6cv","CVE-2026-52724","GO-2026-6013"],"title":"kuma-dp connects to control plane without verifying TLS certificate when no CA is configured","summary":"kuma-dp connects to control plane without verifying TLS certificate when no CA is configured","severity":"medium","vendor":"kumahq","product":"github.com/kumahq/kuma/v2","ecosystem":"go","affected":["github.com/kumahq/kuma/v2 < 2.7.26","github.com/kumahq/kuma/v2 >= 2.8.0, < 2.9.16","github.com/kumahq/kuma/v2 >= 2.10.0, < 2.11.14","github.com/kumahq/kuma/v2 >= 2.12.0, < 2.12.11","github.com/kumahq/kuma/v2 >= 2.13.0, < 2.13.7","github.com/kumahq/kuma <= 1.8.1"],"patched":["github.com/kumahq/kuma/v2 2.7.26","github.com/kumahq/kuma/v2 2.9.16","github.com/kumahq/kuma/v2 2.11.14","github.com/kumahq/kuma/v2 2.12.11","github.com/kumahq/kuma/v2 2.13.7"],"published":"2026-07-16","updated":"2026-08-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wvmp-6r4v-j6cv","references":[{"url":"https://github.com/kumahq/kuma/security/advisories/GHSA-wvmp-6r4v-j6cv"},{"url":"https://github.com/kumahq/kuma/pull/16777"},{"url":"https://github.com/kumahq/kuma/commit/2ecadac1aa2fd8cded4c2ab768949f4c2ec83e2a"},{"url":"https://github.com/kumahq/kuma"}],"tags":["osv","go"],"epss":0.00119,"epssPercentile":0.02014,"ingestedAt":"2026-08-13T19:18:21.569Z","slug":"CVE-2026-18679","body":"## Overview\n\nWhen kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled. The dataplane authentication token is sent over this unverified connection\n\n## Impact\n\nAn on-path attacker can intercept the dataplane authentication token and impersonate the control plane to the data plane, allowing them to inject a forged bootstrap configuration and take over the proxy\n\n## Affected configurations\n\n- Universal mode `kuma-dp` started against an HTTPS control plane without `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT` unset)\n\n## Not affected\n\n- Kubernetes installs done through the standard installers (`kumactl install control-plane` or the official Helm chart). In both cases the control plane's mutating admission webhook injects `KUMA_CONTROL_PLANE_CA_CERT` into every sidecar at pod admission, so each `kuma-dp` starts with the CA already configured\n\n## Workarounds\n\nSet `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT`) on every Universal mode data plane and point it at the control plane's serving CA. Alternatively, terminate the control plane behind a publicly trusted certificate; the patched releases will verify successfully against the operating system trust store with no further configuration\n\n## Resources\n\n- Fix: https://github.com/kumahq/kuma/pull/16777\n\n## Affected packages\n\n- `github.com/kumahq/kuma/v2 < 2.7.26`\n- `github.com/kumahq/kuma/v2 >= 2.8.0, < 2.9.16`\n- `github.com/kumahq/kuma/v2 >= 2.10.0, < 2.11.14`\n- `github.com/kumahq/kuma/v2 >= 2.12.0, < 2.12.11`\n- `github.com/kumahq/kuma/v2 >= 2.13.0, < 2.13.7`\n- `github.com/kumahq/kuma <= 1.8.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/kumahq/kuma/v2 2.7.26`\n- `github.com/kumahq/kuma/v2 2.9.16`\n- `github.com/kumahq/kuma/v2 2.11.14`\n- `github.com/kumahq/kuma/v2 2.12.11`\n- `github.com/kumahq/kuma/v2 2.13.7`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}