TLS Verification Flaw in Kuma by Kong Technologies
CVE-2026-18679
5.8MEDIUM
What is CVE-2026-18679?
A security issue exists in Kuma, a service mesh by Kong Technologies, where the absence of a CA certificate on the HTTPS control plane leads to TLS peer verification being disabled. Consequently, this flaw enables an on-path attacker to intercept the data plane authentication token, posing as the control plane. The attacker can inject a fraudulent bootstrap configuration, giving them control over service proxy operations.
Affected Version(s)
Kong Mesh Linux 0 < 2.7.26
Kong Mesh Linux 2.8.0 < 2.9.16
Kong Mesh Linux 2.10.0 < 2.11.14
