CVE-2026-18677
NONE—CVSS v3
—CVSS v2
0.31%
EPSS (exploit probability)
CWE-290CWE
Description
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Affected routers (0)
No routers currently mapped to this CVE in our database.