What is CVE-2026-18673?
CVE-2026-18673 exposes the Envoy admin API over TCP port 9902 without authentication when kuma-dp uses the default Unix domain socket configuration, making it accessible to any network caller. This allows attackers to access sensitive administrative functions of the Envoy proxy. It is recommended to enable authentication for the readiness service or restrict access to the port to trusted networks only.
Azərbaycanca: CVE-2026-18673, kuma-dp default konfiqurasiyasında Unix domain socket üzərindən işləyən Envoy admin API-ni autentifikasiyasız şəkildə TCP port 9902 üzərindən bütün interfeyslərə açıq qoyur. Bu zəiflik şəbəkədəki hər hansı bir hücumçuya Envoy admin API-nin idarəetmə funksiyalarına giriş imkanı verir. Probleme qarşı kuma-dp konfiqurasiyasında autentifikasiya tələbini aktivləşdirmək və ya portu xarici şəbəkələrə məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
How does CVE-2026-18673 affect the Envoy admin API in kuma-dp?
CVE-2026-18673 exposes the Envoy admin API over TCP port 9902 without authentication when kuma-dp uses the default Unix domain socket configuration.
What mitigation steps are recommended for CVE-2026-18673?
It is recommended to enable authentication for the readiness service or restrict access to the port to trusted networks only.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.