What is CVE-2026-18677?
This CVE describes a flaw in the `kuma-cp` XDS authenticator in Kong Mesh running in universal mode. When a dataplane token is not bound to a workload, the `kuma.io/workload` label used in the SPIFFE ID path template is not validated, potentially leading to unauthorized access. Administrators should enforce mandatory workload binding or apply patches from the vendor.
Azərbaycanca: Bu CVE, Kong Mesh-in universal rejimdə işləyən versiyalarında `kuma-cp` XDS autentifikatorundakı qüsuru təsvir edir. Dataplane token-i iş yükünə bağlanmadıqda, `kuma.io/workload` etiketindən törədilmiş SPIFFE ID yol şablonu düzgün yoxlanılmır, bu da icazəsiz giriş riskinə səbəb ola bilər. Sistem administratorları dərhal token bağlama siyasətlərini məcburi etməli və ya təchizatçıdan əlavə yamaq tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What risk does the CVE-2026-18677 flaw in the `kuma-cp` XDS authenticator pose when Kong Mesh operates in universal mode?
When a dataplane token is not bound to a workload, the SPIFFE ID path template derived from the `kuma.io/workload` label is not properly validated, potentially leading to unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.