Cross-Origin Resource Sharing Misconfiguration in Kong Mesh Reveals Sensitive Information
CVE-2026-18676
5.1MEDIUM
What is CVE-2026-18676?
The default configuration of Kong Mesh contains a critical misconfiguration related to Cross-Origin Resource Sharing (CORS). When the control plane is accessible through a web browser, a malicious web page can exploit this flaw by executing a cross-origin fetch(), which returns the admin bootstrap token and signing keys. This exposes sensitive information, making it possible for an attacker to gain unauthorized access to administrative features and resources. Proper security measures and patches are essential to mitigate this vulnerability.
Affected Version(s)
Kong Mesh Linux 0 < 2.7.25
Kong Mesh Linux 2.8.0 < 2.9.15
Kong Mesh Linux 2.10.0 < 2.11.13
