CVE-2026-18676

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 19:17

Updated : 2026-08-31 19:22


NVD link : CVE-2026-18676

Mitre link : CVE-2026-18676

CVE.ORG link : CVE-2026-18676


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error

CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains