Excessive API Exposure in Kuma Data Plane Due to Unauthenticated Access
CVE-2026-18673
5.3MEDIUM
What is CVE-2026-18673?
The Kuma Data Plane, when set up with the Envoy admin API on a Unix domain socket (the default configuration), exposes its readiness service on TCP port 9902. This configuration allows any caller with network access to this port to retrieve extensive information about Envoy and data plane configurations without the need for authentication. An attacker within the cluster can access configuration dumps, cluster and listener lists, statistics, and the mesh trust bundle. It is important to note that while this exposure is read-only and destructive actions are not permitted, it still poses significant risks to data privacy and system integrity.
Affected Version(s)
Kong Mesh Linux 2.14.0 < 2.14.2
