Excessive API Exposure in Kuma Data Plane Due to Unauthenticated Access
CVE-2026-18673

5.3MEDIUM

Key Information:

Vendor

Kong Inc.

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18673?

The Kuma Data Plane, when set up with the Envoy admin API on a Unix domain socket (the default configuration), exposes its readiness service on TCP port 9902. This configuration allows any caller with network access to this port to retrieve extensive information about Envoy and data plane configurations without the need for authentication. An attacker within the cluster can access configuration dumps, cluster and listener lists, statistics, and the mesh trust bundle. It is important to note that while this exposure is read-only and destructive actions are not permitted, it still poses significant risks to data privacy and system integrity.

Affected Version(s)

Kong Mesh Linux 2.14.0 < 2.14.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://hackerone.com/zoom9797
.