CVE-2026-13341: Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kong Konnect Model Context Protocol (MCP) serverto a version that resolves this vulnerability.Fixed in 1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13341?
The severity of CVE-2026-13341 is rated high with a score of 7.4.
How do I fix CVE-2026-13341?
To fix CVE-2026-13341, upgrade the Kong Konnect MCP server to version 1.0.0 or later.
What symptoms indicate a potential exploitation of CVE-2026-13341?
Symptoms may include unexpected API requests or unusual behavior in applications interacting with the Kong Konnect MCP.
Who is affected by CVE-2026-13341?
Anyone using the Kong Konnect MCP server prior to version 1.0.0 is affected by CVE-2026-13341.
What type of vulnerability is CVE-2026-13341?
CVE-2026-13341 is an indirect prompt injection vulnerability related to input validation.