Transport Layer Security Issue in Kuma by Kong
CVE-2026-50166
5.5MEDIUM
What is CVE-2026-50166?
Kuma is an Envoy-based service mesh that enables communication across various cloud environments, including Kubernetes and VMs. Versions prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7 have a significant security flaw. When using kumactl to configure an HTTPS control plane without the --ca-cert-file flag, TLS peer verification is not enforced. This flaw allows API tokens to be transmitted over unverified connections, making them susceptible to interception by malicious actors on the network. As a result, an attacker could effectively impersonate legitimate users, accessing and manipulating the control plane. It is recommended to upgrade to the latest versions to mitigate this issue.
Affected Version(s)
kuma < 2.7.26
