CVE-2026-18679
MEDIUM
5,8
Source: 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Attack Vector: adjacent
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection.
An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
295
Improper Certificate Validation
DraftCommon Consequences
Security Scopes Affected:
Integrity
Authentication
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Mobile
https://developer.konghq.com/mesh/changelog/
https://github.com/kumahq/kuma/pull/16777
https://github.com/kumahq/kuma/security/advisories/GHSA-wvmp-6r4v-j6cv