What is CVE-2026-18678?
CVE-2026-18678: When an HTTPS profile is added to kumactl without a CA certificate, TLS verification is disabled, causing API tokens to be sent over an unverified connection. An attacker on the network path can intercept these tokens. Affected operators should reconfigure the profile with a CA certificate and revoke any potentially compromised tokens.
Azərbaycanca: CVE-2026-18678: Operator HTTPS profil əlavə edərkən CA sertifikatı təqdim edilmədikdə, kumactl TLS doğrulamasını deaktiv edir və API tokenlərini şifrələnməmiş ötürür. Bu, şəbəkə yolundakı hücumçuya tokenləri ələ keçirməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal CA sertifikatı ilə profili yenidən konfiqurasiya etməli və şübhəli tokenləri ləğv etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
When does CVE-2026-18678 vulnerability occur?
It occurs when an operator adds an HTTPS profile in kumactl without providing a CA certificate.
What can an attacker exploiting this vulnerability gain?
An attacker on the network path can intercept the API tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.