When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.
An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 19:17
Updated : 2026-08-31 19:22
NVD link : CVE-2026-18678
Mitre link : CVE-2026-18678
CVE.ORG link : CVE-2026-18678
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
