In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to Kong Mesh 2.13.10 or 2.14.2, whichever matches your release line. In patched versions a dataplane whose identity derives from the kuma.io/workload label requires a workload-bound token; an unbound tags-only token is rejected at XDS authentication. Kubernetes mode and universal templates that do not reference the workload label keep working with unbound tokens.


Workaround

Issue workload-bound dataplane tokens for every dataplane whose identity derives from the kuma.io/workload label. A workload-bound token constrains that label to the bound value, so a mismatched label is rejected at authentication.

History

Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Title Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Kong

Published:

Updated: 2026-08-12T18:47:06.710Z

Reserved: 2026-08-03T15:20:45.630Z

Link: CVE-2026-18677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T19:17:31.063

Modified: 2026-08-12T19:17:31.063

Link: CVE-2026-18677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses