Cross-zone Isolation Bypass in Kong Mesh Control Plane
CVE-2026-18674
7HIGH
What is CVE-2026-18674?
A vulnerability in Kong Mesh's global control plane allows for cross-zone isolation bypass due to improper attribution of resources received over the zone-to-global KDS sync. Instead of relying on an authenticated zone identity, the system uses a sender-controlled identifier, enabling the holder of credentials from one zone to inject and manipulate resources in another zone's namespace. This weakness stems from the KDS sync code in Kuma, which Kong Mesh's control plane is based on, posing a significant security risk for organizations using this platform.
Affected Version(s)
Kong Mesh Linux 0 < 2.7.29
Kong Mesh Linux 2.8.0 < 2.9.19
Kong Mesh Linux 2.10.0 < 2.11.18
