Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Kong Mesh 2.7.25, 2.9.15, 2.11.13, 2.12.10 or 2.13.5, whichever matches your release line. In patched versions the corsAllowedDomains default changed from [".*"] to [], making CORS opt-in, and localhostIsAdmin was hardened to require a direct loopback RemoteAddr and Host and to reject requests carrying proxy-hop headers (X-Forwarded-For), cross-site fetch metadata (Sec-Fetch-Site), or a non-localhost Origin. The 2.14 line shipped after the fix and was never affected.
Vendor Workaround
Set KUMA_API_SERVER_AUTHN_LOCALHOST_IS_ADMIN=false after retrieving the admin token, set KUMA_API_SERVER_CORS_ALLOWED_DOMAINS to an explicit allowlist such as http://localhost:5681,http://127.0.0.1:5681, and do not run kuma-cp on a machine used to browse untrusted sites.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Konghq
Konghq kong Mesh |
|
| Vendors & Products |
Konghq
Konghq kong Mesh |
Wed, 12 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material. | |
| Title | Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin | |
| Weaknesses | CWE-346 CWE-942 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-08-13T14:50:43.069Z
Reserved: 2026-08-03T15:20:44.526Z
Link: CVE-2026-18676
Updated: 2026-08-13T14:50:40.227Z
Status : Received
Published: 2026-08-12T19:17:30.813
Modified: 2026-08-13T15:19:35.967
Link: CVE-2026-18676
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:48:09Z