๐Ÿ” CVE Alert

CVE-2026-18678

UNKNOWN 0.0

Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.

CWE CWE-295
Vendor kong inc.
Product kong mesh
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for kong inc. kong mesh

Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Kong Inc. / Kong Mesh
0 < 2.7.26 2.8.0 < 2.9.16 2.10.0 < 2.11.14 2.12.0 < 2.12.11 2.13.0 < 2.13.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-v95x-xhq5-4929 github.com: https://github.com/kumahq/kuma/pull/16777 developer.konghq.com: https://developer.konghq.com/mesh/changelog/