What is CVE-2026-18676?
A CORS misconfiguration in the default kuma-cp configuration of Kong Mesh exposes the admin bootstrap token and signing keys. When the control plane is reachable from an operator's browser, a malicious webpage can exploit this to retrieve the admin JWT and signing keys via a cross-origin request. Operators should immediately restrict CORS settings.
Azərbaycanca: Kong Mesh-in standart kuma-cp konfiqurasiyasında CORS səhv konfiqurasiyası aşkar edilib. Bu boşluq operatorun brauzerindən idarəetmə panelinə (control plane) bağlanarkən zərərli səhifənin admin bootstrap tokeni və imza açarlarını əldə etməsinə imkan verir. Operatorlar dərhal CORS parametrlərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What vulnerability in Kong Mesh’s default kuma-cp configuration can lead to the theft of the admin bootstrap token?
A CORS misconfiguration in the default kuma-cp configuration allows the admin bootstrap token and signing keys to be retrieved. When the control plane is reachable from an operator's browser, a malicious webpage can obtain the admin JWT via a cross-origin request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.