Cross-zone Isolation Bypass in Kong Mesh Control Plane
CVE-2026-18674

7HIGH

Key Information:

Vendor

Kong Inc.

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-18674?

A vulnerability in Kong Mesh's global control plane allows for cross-zone isolation bypass due to improper attribution of resources received over the zone-to-global KDS sync. Instead of relying on an authenticated zone identity, the system uses a sender-controlled identifier, enabling the holder of credentials from one zone to inject and manipulate resources in another zone's namespace. This weakness stems from the KDS sync code in Kuma, which Kong Mesh's control plane is based on, posing a significant security risk for organizations using this platform.

Affected Version(s)

Kong Mesh Linux 0 < 2.7.29

Kong Mesh Linux 2.8.0 < 2.9.19

Kong Mesh Linux 2.10.0 < 2.11.18

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johanw
.