CVE-2026-18677: Kong Inc Kong Mesh
Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Affected products
- Kong Inc Kong Mesh: from 2.13.0, before 2.13.10 (fixed in 2.13.10); from 2.14.0, before 2.14.2 (fixed in 2.14.2)
Published 2026-08-12. Last modified 2026-08-31.