VulnerabilityAwaiting Analysis
CVE-2026-18678
An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
MEDIUM 5.5EPSS 0.10%
Does this matter?
Lower severity and a low EPSS score (0.10%). Track it; it rarely justifies an emergency change on its own.
Description
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.10% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Source
- 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.