KubeEdge CloudCore versions through 1.23.1 contain a missing authentication vulnerability on its HTTPS server's node task status reporting endpoint. Attackers can access port 10002 without any authentication to submit fraudulent node task status reports. This allows adversaries to falsely mark upgrade jobs as succeeded or failed, deceiving the Kubernetes control plane about the actual state of edge node upgrades. The manipulation can block legitimate upgrade scheduling, disrupting edge node management operations. The vulnerability resides in the CloudHub HTTP server's node task report status handler. No credentials or tokens are required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The issue affects the cloud-side component of KubeEdge, an open-source framework extending Kubernetes capabilities to edge devices. Exploitation could lead to persistent disruption of edge node lifecycle management and upgrade orchestration.