Junglewise Threat Intelligence
CVE-2026-18678: GO-2026-6010 - kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
CVE-2026-18678 · Severity: medium · CVSS 4 · Published 2026-07-22
Technologies: github.com/kumahq/kuma (Go), github.com/kumahq/kuma/v2 (Go). Vendors: Go.
Executive brief
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
Affected products
- Go github.com/kumahq/kuma
- Go github.com/kumahq/kuma/v2
CVE identifiers
- CVE-2026-18678
- CVE-2026-50166