๐Ÿ” CVE Alert

CVE-2026-18677

UNKNOWN 0.0

Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.

CWE CWE-290
Vendor kong inc.
Product kong mesh
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for kong inc. kong mesh

Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Kong Inc. / Kong Mesh
2.13.0 < 2.13.10 2.14.0 < 2.14.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-744g-c785-x65q github.com: https://github.com/kumahq/kuma/pull/17474 github.com: https://github.com/kumahq/kuma/pull/17503 github.com: https://github.com/kumahq/kuma/pull/17502 developer.konghq.com: https://developer.konghq.com/mesh/changelog/

Credits

kanywst