Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to Kong Mesh 2.13.10 or 2.14.2, whichever matches your release line. In patched versions a dataplane whose identity derives from the kuma.io/workload label requires a workload-bound token; an unbound tags-only token is rejected at XDS authentication. Kubernetes mode and universal templates that do not reference the workload label keep working with unbound tokens.
Workaround
Issue workload-bound dataplane tokens for every dataplane whose identity derives from the kuma.io/workload label. A workload-bound token constrains that label to the bound value, so a mismatched label is rejected at authentication.
Wed, 12 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity. | |
| Title | Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-08-12T18:47:06.710Z
Reserved: 2026-08-03T15:20:45.630Z
Link: CVE-2026-18677
No data.
Status : Received
Published: 2026-08-12T19:17:31.063
Modified: 2026-08-12T19:17:31.063
Link: CVE-2026-18677
No data.
OpenCVE Enrichment
No data.