CVE-2026-18679: Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection.
An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kong Mesh (kuma-dp)to a version that resolves this vulnerability.Fixed in 2.7.26 - Upgrade
Upgrade
Kong Mesh (kuma-dp)to a version that resolves this vulnerability.Fixed in 2.9.16 - Upgrade
Upgrade
Kong Mesh (kuma-dp)to a version that resolves this vulnerability.Fixed in 2.11.14 - Upgrade
Upgrade
Kong Mesh (kuma-dp)to a version that resolves this vulnerability.Fixed in 2.12.11 - Upgrade
Upgrade
Kong Mesh (kuma-dp)to a version that resolves this vulnerability.Fixed in 2.13.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18679?
The severity of CVE-2026-18679 is rated at 77, indicating a high risk level.
How do I fix CVE-2026-18679?
To fix CVE-2026-18679, ensure that a valid CA certificate is provided when starting kuma-dp to enforce TLS peer verification.
What impact does CVE-2026-18679 have on Kong Mesh users?
CVE-2026-18679 allows an on-path actor to intercept data plane authentication tokens, leading to potential unauthorized access.
In which software is CVE-2026-18679 found?
CVE-2026-18679 is found in Kong Mesh, specifically affecting the kuma-dp component.
When was CVE-2026-18679 published?
CVE-2026-18679 was published on August 12, 2026.