CVE-2026-18674

Published: Ago 17, 2026 Last Modified: Ago 17, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,0
Source: 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.

The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide.

The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.

345

Insufficient Verification of Data Authenticity

Draft
Common Consequences
Security Scopes Affected:
Integrity Other
Potential Impacts:
Varies By Context Unexpected State
Applicable Platforms
Technologies: ICS/OT
View CWE Details
863

Incorrect Authorization

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Access Control Availability
Potential Impacts:
Read Application Data Read Files Or Directories Modify Application Data Modify Files Or Directories Gain Privileges Or Assume Identity Bypass Protection Mechanism Execute Unauthorized Code Or Commands Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other)
Applicable Platforms
Technologies: Web Server, Database Server, Not Technology-Specific
View CWE Details
https://developer.konghq.com/mesh/changelog/
https://github.com/kumahq/kuma/pull/17456
https://github.com/kumahq/kuma/pull/17458
https://github.com/kumahq/kuma/pull/17459
https://github.com/kumahq/kuma/pull/17460
https://github.com/kumahq/kuma/pull/17461
https://github.com/kumahq/kuma/pull/17462
https://github.com/kumahq/kuma/pull/17463
https://github.com/kumahq/kuma/security/advisories/GHSA-m58j-fjmc-h3g4