Authentication Bypass in KubeEdge CloudCore Affects Node Task Reporting
CVE-2026-82473
Key Information:
Badges
What is CVE-2026-82473?
The KubeEdge CloudCore component, up to version 1.23.1, is vulnerable to an authentication bypass that allows attackers to submit node task status reports without any authentication. This flaw is exploitable via the HTTPS service on port 10002, enabling unauthorized users to manipulate the perceived upgrade status of nodes. Consequently, this can result in misleading information about successful or failed upgrades, potentially disrupting upgrade schedules and impacting overall system reliability.
Affected Version(s)
kubeedge 0 <= 1.23.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
