CVE-2026-18677
MEDIUM
6,0
Source: 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
290
Authentication Bypass by Spoofing
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://developer.konghq.com/mesh/changelog/
https://github.com/kumahq/kuma/pull/17474
https://github.com/kumahq/kuma/pull/17502
https://github.com/kumahq/kuma/pull/17503
https://github.com/kumahq/kuma/security/advisories/GHSA-744g-c785-x65q