What is CVE-2026-18679?
CVE-2026-18679 is a vulnerability where kuma-dp disables TLS peer verification when connecting to an HTTPS control plane without a provided CA certificate. This allows an on-path actor to intercept the dataplane authentication token. Operators must ensure a CA certificate is passed during startup.
Azərbaycanca: CVE-2026-18679 Kuma-dp-də HTTPS idarəetmə müstəvisinə qoşularkən CA sertifikatı təqdim edilmədikdə TLS peer doğrulamasının deaktiv edilməsi zəifliyidir. Bu, on-path aktora dataplane autentifikasiya tokenini ələ keçirməyə imkan verir. Operatorların CA sertifikatı təmin etməsi mütləqdir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Under what circumstances does CVE-2026-18679 vulnerability occur in kuma-dp?
This vulnerability occurs when connecting to an HTTPS control plane without providing a CA certificate during kuma-dp startup.
What is the potential impact if CVE-2026-18679 is exploited?
Exploitation could allow an on-path actor to intercept the dataplane authentication token.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.