CVE-2026-18679
Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
| CWE | CWE-295 |
| Vendor | kong inc. |
| Product | kong mesh |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for kong inc. kong mesh
Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Kong Inc. / Kong Mesh
0 < 2.7.26 2.8.0 < 2.9.16 2.10.0 < 2.11.14 2.12.0 < 2.12.11 2.13.0 < 2.13.7