CVE-2026-52724Medium· 5.8▾ SunlitKuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer ve…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 5.8
0.2%
0.2% → 0.4%
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is unset. The dataplane authentication token is sent over the unverified connection, allowing an on-path attacker to intercept the token, impersonate the control plane, inject a forged bootstrap configuration, and take over the proxy. Standard Kubernetes installations created by kumactl install control-plane or the official Helm chart are unaffected because the mutating admission webhook injects KUMA_CONTROL_PLANE_CA_CERT into each sidecar. This issue is fixed in versions 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/kumahq/kuma/v2 < 2.7.26github.com/kumahq/kuma/v2 >= 2.8.0, < 2.9.16github.com/kumahq/kuma/v2 >= 2.10.0, < 2.11.14github.com/kumahq/kuma/v2 >= 2.12.0, < 2.12.11github.com/kumahq/kuma/v2 >= 2.13.0, < 2.13.7github.com/kumahq/kuma <= 1.8.1Patched in:
github.com/kumahq/kuma/v2 2.7.26github.com/kumahq/kuma/v2 2.9.16github.com/kumahq/kuma/v2 2.11.14github.com/kumahq/kuma/v2 2.12.11github.com/kumahq/kuma/v2 2.13.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50166Medium· 5.5Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
CVE-2026-18679Mediumkuma-dp connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-18678Mediumkumactl connects to control plane without verifying TLS certificate when no CA is configured
CVE-2021-20327Medium· 6.4A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate
CVE-2026-81871Medium· 6.3OpenTelemetry-Go is the Go implementation of OpenTelemetry
CVE-2026-18676MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin