CVE-2026-82473
nicheUnauthenticated task status spoofing in KubeEdge CloudCore
KubeEdge CloudCore through version 1.23.1 accepts node task status reports on its HTTPS server without verifying authentication (CWE-306, Missing Authentication for Critical Function). An attacker who can reach CloudCore on port 10002 can submit forged reports that mark node upgrade jobs as succeeded or failed. This deceives the control plane about actual node upgrade status and can block or derail further upgrade scheduling, an integrity impact on upgrade task data with no effect on confidentiality. Any KubeEdge deployment running CloudCore 1.23.1 or earlier is affected, with the greatest risk where port 10002 is reachable from untrusted networks. No exploitation is currently known: there is no public proof of concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Restrict network access to CloudCore port 10002 to trusted cluster components using firewall rules, security groups, or network policies, and review recent node upgrade task statuses for forged success/failure reports. Upgrade CloudCore to the first patched release after 1.23.1 as soon as one is published, since the advisory data does not yet name a fixed version. Monitor KubeEdge and VulnCheck channels for patch availability, PoC releases, and any addition to CISA KEV.
| KubeEdge CloudCore | through 1.23.1 (all versions up to and including 1.23.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.