CVE-2026-18678

MEDIUM CVSS 4.0: 5.5 EPSS 0.10%
Updated Aug 13, 2026
Kong Inc.
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-295 (Improper Certificate Validation)
Vendor Kong Inc.
Public PoC No

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

kong inc.:kong mesh