CVE-2026-18677

NONE
CVSS v3
CVSS v2
0.31% EPSS (exploit probability)
CWE-290CWE

Description

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references