ZeroHour

CVE-2026-82473

niche

Unauthenticated task status spoofing in KubeEdge CloudCore

CVSS 4.0
8.8 high
EPSS
<1%p29
Published
()
Modified
AI analysis

KubeEdge CloudCore through version 1.23.1 accepts node task status reports on its HTTPS server without verifying authentication (CWE-306, Missing Authentication for Critical Function). An attacker who can reach CloudCore on port 10002 can submit forged reports that mark node upgrade jobs as succeeded or failed. This deceives the control plane about actual node upgrade status and can block or derail further upgrade scheduling, an integrity impact on upgrade task data with no effect on confidentiality. Any KubeEdge deployment running CloudCore 1.23.1 or earlier is affected, with the greatest risk where port 10002 is reachable from untrusted networks. No exploitation is currently known: there is no public proof of concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Restrict network access to CloudCore port 10002 to trusted cluster components using firewall rules, security groups, or network policies, and review recent node upgrade task statuses for forged success/failure reports. Upgrade CloudCore to the first patched release after 1.23.1 as soon as one is published, since the advisory data does not yet name a fixed version. Monitor KubeEdge and VulnCheck channels for patch availability, PoC releases, and any addition to CISA KEV.

Affected
KubeEdge CloudCorethrough 1.23.1 (all versions up to and including 1.23.1)
Estimated exposure
nichelikely hundreds to low thousands of KubeEdge deployments, with only those exposing CloudCore port 10002 to untrusted networks directly attackable; no published… — KubeEdge is a specialized CNCF edge-Kubernetes project with no published active-install counts, and the flaw is only exploitable where CloudCore's port 10002 is network-reachable to an attacker, which most operators keep private.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.