


Perceptive Security
SOC/SIEM Consultancy

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on por…
Published:
29 augustus 2026 om 00:00:00
Alert date:
29 augustus 2026 om 20:03:20
Source:
nvd.nist.gov
Cloud & Virtualization, Mobile & IoT, Identity & Access
KubeEdge CloudCore versions through 1.23.1 contain a missing authentication vulnerability on its HTTPS server's node task status reporting endpoint. Attackers can access port 10002 without any authentication to submit fraudulent node task status reports. This allows adversaries to falsely mark upgrade jobs as succeeded or failed, deceiving the Kubernetes control plane about the actual state of edge node upgrades. The manipulation can block legitimate upgrade scheduling, disrupting edge node management operations. The vulnerability resides in the CloudHub HTTP server's node task report status handler. No credentials or tokens are required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The issue affects the cloud-side component of KubeEdge, an open-source framework extending Kubernetes capabilities to edge devices. Exploitation could lead to persistent disruption of edge node lifecycle management and upgrade orchestration.
Technical details
Mitigation steps:
Affected products:
KubeEdge CloudCore 1.23.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82473
https://github.com/geo-chen/oss/blob/main/kubeedge.md
https://github.com/kubeedge/kubeedge
https://github.com/kubeedge/kubeedge/blob/v1.23.1/cloud/pkg/cloudhub/servers/httpserver/nodetask/report_status.go
https://github.com/kubeedge/kubeedge/blob/v1.23.1/cloud/pkg/cloudhub/servers/httpserver/server.go
https://www.vulncheck.com/advisories/kubeedge-cloudcore-through-1.23.1-missing-authentication-on-node-task-endpoints
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
