๐Ÿ” CVE Alert

CVE-2026-18676

UNKNOWN 0.0

Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser.ย Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

CWE CWE-346 CWE-942
Vendor kong inc.
Product kong mesh
Published Aug 12, 2026
Last Updated Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for kong inc. kong mesh

Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Kong Inc. / Kong Mesh
0 < 2.7.25 2.8.0 < 2.9.15 2.10.0 < 2.11.13 2.12.0 < 2.12.10 2.13.0 < 2.13.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-3vcp-chfh-f6r2 github.com: https://github.com/kumahq/kuma/pull/16416 github.com: https://github.com/kumahq/kuma/pull/16423 github.com: https://github.com/kumahq/kuma/pull/16424 github.com: https://github.com/kumahq/kuma/pull/16425 github.com: https://github.com/kumahq/kuma/pull/16426 github.com: https://github.com/kumahq/kuma/pull/16427 developer.konghq.com: https://developer.konghq.com/mesh/changelog/

Credits

eldudareeno