Junglewise Threat Intelligence

CVE-2026-18678: GO-2026-6010 - kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

CVE-2026-18678 · Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: github.com/kumahq/kuma (Go), github.com/kumahq/kuma/v2 (Go). Vendors: Go.

Executive brief

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

Affected products

  • Go github.com/kumahq/kuma
  • Go github.com/kumahq/kuma/v2

CVE identifiers

  • CVE-2026-18678
  • CVE-2026-50166

Related threats