CVE-2026-18679: Kong Inc Kong Mesh
Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
Affected products
- Kong Inc Kong Mesh: before 2.7.26 (fixed in 2.7.26); from 2.8.0, before 2.9.16 (fixed in 2.9.16); from 2.10.0, before 2.11.14 (fixed in 2.11.14); from 2.12.0, before 2.12.11 (fixed in 2.12.11); from 2.13.0, before 2.13.7 (fixed in 2.13.7)
Published 2026-08-12. Last modified 2026-08-31.