CVE-2026-18676

MEDIUM CVSS 4.0: 5.1 EPSS 0.23%
Updated Aug 13, 2026
Kong Inc.
Parameter Value
CVSS 5.1 (MEDIUM)
Type CWE-942, CWE-346 (Origin Validation Error)
Vendor Kong Inc.
Public PoC No

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

kong inc.:kong mesh