XDS Authenticator Vulnerability in Kong Mesh
CVE-2026-18677
6MEDIUM
What is CVE-2026-18677?
In Kong Mesh operating in universal mode, an XDS authenticator vulnerability has been identified, which involves the validation of workload labels derived from a specific SPIFFE ID path template. The XDS authenticator currently only verifies these labels when the dataplane token is legitimately bound to a workload. Since binding is optional, this flaw allows a potentially malicious dataplane with a tags-bound token to impersonate another workload by misrepresenting its kuma.io/workload label. This presents risks in environments relying on Kubernetes-based deployments for workload management and security.
Affected Version(s)
Kong Mesh Linux 2.13.0 < 2.13.10
Kong Mesh Linux 2.14.0 < 2.14.2
