CVE-2026-45021: Kumahq Kuma
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. CorsAllowedDomains: [".*"] reflects any Origin, and LocalhostIsAdmin: true promotes requests from 127.0.0.1 to mesh-system:admin. A cross-origin fetch() from a malicious page returns the admin JWT and signing material. This vulnerability is fixed in 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5.
Affected products
- Kumahq Kuma: before 2.7.25 (fixed in 2.7.25); from 2.9.0, before 2.9.15 (fixed in 2.9.15); from 2.11.0, before 2.11.13 (fixed in 2.11.13); from 2.12.0, before 2.12.10 (fixed in 2.12.10); from 2.13.0, before 2.13.5 (fixed in 2.13.5)
Published 2026-05-28. Last modified 2026-06-17.