๐Ÿ” CVE Alert

CVE-2026-18679

UNKNOWN 0.0

Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.

CWE CWE-295
Vendor kong inc.
Product kong mesh
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for kong inc. kong mesh

Be the first to know when new unknown vulnerabilities affecting kong inc. kong mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Kong Inc. / Kong Mesh
0 < 2.7.26 2.8.0 < 2.9.16 2.10.0 < 2.11.14 2.12.0 < 2.12.11 2.13.0 < 2.13.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kumahq/kuma/security/advisories/GHSA-wvmp-6r4v-j6cv github.com: https://github.com/kumahq/kuma/pull/16777 developer.konghq.com: https://developer.konghq.com/mesh/changelog/