Cross-Origin Resource Sharing Misconfiguration in Kong Mesh Reveals Sensitive Information
CVE-2026-18676

5.1MEDIUM

Key Information:

Vendor

Kong Inc.

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18676?

The default configuration of Kong Mesh contains a critical misconfiguration related to Cross-Origin Resource Sharing (CORS). When the control plane is accessible through a web browser, a malicious web page can exploit this flaw by executing a cross-origin fetch(), which returns the admin bootstrap token and signing keys. This exposes sensitive information, making it possible for an attacker to gain unauthorized access to administrative features and resources. Proper security measures and patches are essential to mitigate this vulnerability.

Affected Version(s)

Kong Mesh Linux 0 < 2.7.25

Kong Mesh Linux 2.8.0 < 2.9.15

Kong Mesh Linux 2.10.0 < 2.11.13

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

eldudareeno
.