What is CVE-2026-18674?
The CVE-2026-18674 vulnerability was discovered in Kong Mesh global control plane. The flaw occurs because resources during zone-to-global KDS sync are attributed using the sender-controlled ControlPlane.Identifier instead of the authenticated zone identity from the connection. This could allow authenticated zones to store arbitrary data on the global control plane; immediate patching is required.
Azərbaycanca: CVE-2026-18674 zəifliyi Kong Mesh global control plane-də aşkarlanıb. Zəiflik, zone-to-global KDS sync zamanı resursların autentifikasiya olunmuş zona identikatoru əvəzinə göndərən tərəfindən idarə olunan ControlPlane.Identifier ilə əlaqələndirilməsi səbəbindən baş verir. Bu, autentifikasiya olunmuş zonalara global control plane-də özbaşına məlumat saxlamağa imkan verə bilər, dərhal patç tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
What causes the misattribution of resources in the CVE-2026-18674 vulnerability in Kong Mesh?
During zone-to-global KDS sync, resources are attributed using the sender-controlled ControlPlane.Identifier instead of the authenticated zone identity from the connection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.