cvedb.io
CVE-2026-18678
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2026-08-12T19:17:31.323 · Last modified 2026-08-12T19:17:31.323

Summary

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.