CVE-2026-18677

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 19:17

Updated : 2026-08-31 19:22


NVD link : CVE-2026-18677

Mitre link : CVE-2026-18677

CVE.ORG link : CVE-2026-18677


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing