An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.
Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to Kong Mesh 2.14.2. In patched versions the readiness reporter serves only /ready; the Envoy admin API stays on the Unix domain socket, which is not reachable over the pod network.
Workaround
Restrict network access to port 9902 to trusted monitoring only, for example with a Kubernetes NetworkPolicy.
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication. An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed. | |
| Title | Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication | |
| Weaknesses | CWE-200 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-08-12T18:20:33.205Z
Reserved: 2026-08-03T15:18:30.454Z
Link: CVE-2026-18673
No data.
Status : Received
Published: 2026-08-12T19:17:30.480
Modified: 2026-08-12T19:17:30.480
Link: CVE-2026-18673
No data.
OpenCVE Enrichment
No data.