CVE-2026-18676

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

Scoring

Severity
MEDIUM
CVSS base score
5.1
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.23%
CWE
CWE-346, CWE-942
Published
2026-08-12
Last modified
2026-08-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs