Transport Layer Security Issue in Kuma by Kong
CVE-2026-50166

5.5MEDIUM

Key Information:

Vendor

Kumahq

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-50166?

Kuma is an Envoy-based service mesh that enables communication across various cloud environments, including Kubernetes and VMs. Versions prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7 have a significant security flaw. When using kumactl to configure an HTTPS control plane without the --ca-cert-file flag, TLS peer verification is not enforced. This flaw allows API tokens to be transmitted over unverified connections, making them susceptible to interception by malicious actors on the network. As a result, an attacker could effectively impersonate legitimate users, accessing and manipulating the control plane. It is recommended to upgrade to the latest versions to mitigate this issue.

Affected Version(s)

kuma < 2.7.26

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.