CVE-2026-18677
Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
| CWE | CWE-290 |
| Vendor | kong inc. |
| Product | kong mesh |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for kong inc. kong mesh
Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Kong Inc. / Kong Mesh
2.13.0 < 2.13.10 2.14.0 < 2.14.2
References
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-744g-c785-x65q github.com: https://github.com/kumahq/kuma/pull/17474 github.com: https://github.com/kumahq/kuma/pull/17503 github.com: https://github.com/kumahq/kuma/pull/17502 developer.konghq.com: https://developer.konghq.com/mesh/changelog/
Credits
kanywst