Vulnerability Description
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Related Weaknesses (CWE)
References
- https://developer.konghq.com/mesh/changelog/
- https://github.com/kumahq/kuma/pull/17474
- https://github.com/kumahq/kuma/pull/17502
- https://github.com/kumahq/kuma/pull/17503
- https://github.com/kumahq/kuma/security/advisories/GHSA-744g-c785-x65q
FAQ
What is CVE-2026-18677?
CVE-2026-18677 is a documented vulnerability. In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only...
How severe is CVE-2026-18677?
CVSS scoring is not yet available for CVE-2026-18677. Check NVD for updates.
Is there a patch for CVE-2026-18677?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.