XDS Authenticator Vulnerability in Kong Mesh
CVE-2026-18677

6MEDIUM

Key Information:

Vendor

Kong Inc.

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-18677?

In Kong Mesh operating in universal mode, an XDS authenticator vulnerability has been identified, which involves the validation of workload labels derived from a specific SPIFFE ID path template. The XDS authenticator currently only verifies these labels when the dataplane token is legitimately bound to a workload. Since binding is optional, this flaw allows a potentially malicious dataplane with a tags-bound token to impersonate another workload by misrepresenting its kuma.io/workload label. This presents risks in environments relying on Kubernetes-based deployments for workload management and security.

Affected Version(s)

Kong Mesh Linux 2.13.0 < 2.13.10

Kong Mesh Linux 2.14.0 < 2.14.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kanywst
.