CVE-2026-18676: Kong Inc Kong Mesh
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.
Affected products
- Kong Inc Kong Mesh: before 2.7.25 (fixed in 2.7.25); from 2.8.0, before 2.9.15 (fixed in 2.9.15); from 2.10.0, before 2.11.13 (fixed in 2.11.13); from 2.12.0, before 2.12.10 (fixed in 2.12.10); from 2.13.0, before 2.13.5 (fixed in 2.13.5)
Published 2026-08-12. Last modified 2026-08-31.