CVE-2026-82473

Source
https://cve.org/CVERecord?id=CVE-2026-82473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82473
Published
2026-08-29T16:35:33.159Z
Modified
2026-09-01T03:30:44.329139102Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints
Details

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82473.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ]
}
References

Affected packages

Git / github.com/kubeedge/kubeedge

Affected ranges

Type
GIT
Repo
https://github.com/kubeedge/kubeedge
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.23.1"
        },
        {
            "fixed": "1.23.1"
        }
    ]
}

Affected versions

v0.*
v0.1
v0.2
v0.2.1
v0.3.0-beta.0
v1.*
v1.0.0
v1.1.0-beta.0
v1.10.0-beta.0
v1.11.0-alpha.0
v1.11.0-beta.0
v1.12.0-beta.0
v1.13.0-beta.0
v1.14.0
v1.14.0-beta.0
v1.15.0-beta.0
v1.16.0-beta.0
v1.17.0-beta.0
v1.18.0-beta.0
v1.19.0-beta.0
v1.2.0-beta.0
v1.20.0-beta.0
v1.21.0-beta.0
v1.22.0-beta.0
v1.23.0
v1.23.0-beta.0
v1.3.0
v1.3.0-alpha.0
v1.3.0-beta.0
v1.4.0-alpha.0
v1.4.0-beta.0
v1.5.0-beta.0
v1.6.0-beta.0
v1.7.0
v1.7.0-beta.0
v1.8.0-beta.0
v1.9.0
v1.9.0-beta.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82473.json"