<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cncf:kubeedge_cloudcore:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acncfkubeedge_cloudcore/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 29 Aug 2026 17:41:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acncfkubeedge_cloudcore/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in KubeEdge CloudCore Node Task Reporting</title><link>https://feed.craftedsignal.io/briefs/2026-08-kubeedge-auth-bypass/</link><pubDate>Sat, 29 Aug 2026 17:41:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-kubeedge-auth-bypass/</guid><description>KubeEdge CloudCore versions through 1.23.1 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to manipulate node upgrade status reports via port 10002.</description><content:encoded><![CDATA[<p>KubeEdge CloudCore versions up to 1.23.1 are susceptible to an authentication bypass vulnerability. The CloudCore component exposes an HTTPS server on port 10002 that fails to properly verify the authenticity of incoming node task status reports. An unauthenticated attacker with network access to this port can submit crafted requests to the control plane, masquerading as a node. By injecting false success or failure status messages for node upgrade jobs, an attacker can deceive the control plane's state machine. This manipulation disrupts the orchestration logic, effectively causing a denial of service regarding the automated scheduling and execution of future node upgrades within the KubeEdge cluster. The issue represents a significant risk to environment management and fleet maintenance operations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthorized party to disrupt cluster management operations by poisoning the status of node upgrade tasks. This results in the blocking of legitimate upgrade schedules across the affected KubeEdge deployment, potentially leaving nodes running outdated, vulnerable, or incompatible software versions. While no massive data breach is immediately associated with this vulnerability, the loss of control over cluster state management poses a high impact to system availability and maintenance integrity in environments relying on KubeEdge for automated lifecycle management.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate mitigation of the vulnerability identified in CVE-2026-82473.</p>
<ul>
<li>Upgrade KubeEdge CloudCore to a version greater than 1.23.1 immediately to incorporate the necessary authentication checks for task status reports.</li>
<li>Restrict network access to CloudCore port 10002. Only trusted edge node communication paths should be permitted to reach this port at the network layer.</li>
<li>Implement host-based or network-level firewall policies to prevent unauthorized subnets or external entities from reaching the management interface of the CloudCore service.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-native</category><category>kubernetes</category></item></channel></rss>