{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kubeedge-cloudcore--1.23.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cncf:kubeedge_cloudcore:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-82473"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KubeEdge CloudCore (\u003c= 1.23.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-native","kubernetes"],"_cs_type":"advisory","_cs_vendors":["CNCF"],"content_html":"\u003cp\u003eKubeEdge CloudCore versions up to 1.23.1 are susceptible to an authentication bypass vulnerability. The CloudCore component exposes an HTTPS server on port 10002 that fails to properly verify the authenticity of incoming node task status reports. An unauthenticated attacker with network access to this port can submit crafted requests to the control plane, masquerading as a node. By injecting false success or failure status messages for node upgrade jobs, an attacker can deceive the control plane's state machine. This manipulation disrupts the orchestration logic, effectively causing a denial of service regarding the automated scheduling and execution of future node upgrades within the KubeEdge cluster. The issue represents a significant risk to environment management and fleet maintenance operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthorized party to disrupt cluster management operations by poisoning the status of node upgrade tasks. This results in the blocking of legitimate upgrade schedules across the affected KubeEdge deployment, potentially leaving nodes running outdated, vulnerable, or incompatible software versions. While no massive data breach is immediately associated with this vulnerability, the loss of control over cluster state management poses a high impact to system availability and maintenance integrity in environments relying on KubeEdge for automated lifecycle management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate mitigation of the vulnerability identified in CVE-2026-82473.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade KubeEdge CloudCore to a version greater than 1.23.1 immediately to incorporate the necessary authentication checks for task status reports.\u003c/li\u003e\n\u003cli\u003eRestrict network access to CloudCore port 10002. Only trusted edge node communication paths should be permitted to reach this port at the network layer.\u003c/li\u003e\n\u003cli\u003eImplement host-based or network-level firewall policies to prevent unauthorized subnets or external entities from reaching the management interface of the CloudCore service.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:41:16Z","date_published":"2026-08-29T17:41:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kubeedge-auth-bypass/","summary":"KubeEdge CloudCore versions through 1.23.1 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to manipulate node upgrade status reports via port 10002.","title":"Authentication Bypass in KubeEdge CloudCore Node Task Reporting","url":"https://feed.craftedsignal.io/briefs/2026-08-kubeedge-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - KubeEdge CloudCore (\u003c= 1.23.1)","version":"https://jsonfeed.org/version/1.1"}