Security Advisory

CVE-2026-18677

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-12 18:47:06
Last updated 2026-08-13 14:49:27
Assigner Kong
CVSS score 6.0
State PUBLISHED

Description

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.