CVE-2026-18678

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 19:17

Updated : 2026-08-31 19:22


NVD link : CVE-2026-18678

Mitre link : CVE-2026-18678

CVE.ORG link : CVE-2026-18678


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation