CVE-2026-18676

Summary

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

Affected Software

VendorProductVersion RangeStatus
Kong Inc.Kong Mesh0 < 2.7.25affected
Kong Inc.Kong Mesh2.8.0 < 2.9.15affected
Kong Inc.Kong Mesh2.10.0 < 2.11.13affected
Kong Inc.Kong Mesh2.12.0 < 2.12.10affected
Kong Inc.Kong Mesh2.13.0 < 2.13.5affected

Weaknesses

  • CWE-346: CWE-346 Origin Validation Error
  • CWE-942: CWE-942 Permissive Cross-domain Policy with Untrusted Domain

Workarounds

Set KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false after retrieving the admin token, set KUMA_API_SERVER_CORS_ALLOWED_DOMAINS to an explicit allowlist such as http://localhost:5681,http://127.0.0.1:5681, and do not run kuma-cp on a machine used to browse untrusted sites.

References