CVE-2026-18674
HIGH
7,0
Source: 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.
The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide.
The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.
345
Insufficient Verification of Data Authenticity
DraftCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Varies By Context
Unexpected State
Applicable Platforms
Technologies:
ICS/OT
863
Incorrect Authorization
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Availability
Potential Impacts:
Read Application Data
Read Files Or Directories
Modify Application Data
Modify Files Or Directories
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Applicable Platforms
Technologies:
Web Server, Database Server, Not Technology-Specific
https://developer.konghq.com/mesh/changelog/
https://github.com/kumahq/kuma/pull/17456
https://github.com/kumahq/kuma/pull/17458
https://github.com/kumahq/kuma/pull/17459
https://github.com/kumahq/kuma/pull/17460
https://github.com/kumahq/kuma/pull/17461
https://github.com/kumahq/kuma/pull/17462
https://github.com/kumahq/kuma/pull/17463
https://github.com/kumahq/kuma/security/advisories/GHSA-m58j-fjmc-h3g4