{"id":"CVE-2026-18674","summary":"Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifier","details":"On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.\n\n\n\nThe result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide.\n\n\n\n\nThe root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.","aliases":["GHSA-m58j-fjmc-h3g4"],"modified":"2026-08-19T03:48:10.324203404Z","published":"2026-08-17T12:08:11.470Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18674.json","cna_assigner":"Kong","cwe_ids":["CWE-345","CWE-863"]},"references":[{"type":"ADVISORY","url":"https://developer.konghq.com/mesh/changelog/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18674.json"},{"type":"ADVISORY","url":"https://github.com/kumahq/kuma/security/advisories/GHSA-m58j-fjmc-h3g4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18674"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17456"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17458"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17459"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17460"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17461"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17462"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17463"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kumahq/kuma","events":[{"introduced":"0"},{"fixed":"c78f8227948b4fef45b8fc0064fa9495230c6cbb"},{"introduced":"1110a0305eec00f1b2fd7482d6df4f3dd6a9d78e"},{"fixed":"924476e2052f5c5eb92d339db5231c610e674e1f"},{"introduced":"fed2256136e694d2a5deedb2490d382ee280fbbe"},{"fixed":"8b1e524df3039708e30c9f83747ac18a700adc0c"},{"introduced":"6b4779917a9f9f9a73ef959a22e243b9a14b4ba1"},{"fixed":"5e0c4351748645fa7164c4b8fbf6521e84c73861"},{"introduced":"99bb946e09bcdf7f7e6c1275c8bf14206db77274"},{"fixed":"b9b8c3f84ad8ff5fede09577439eb12cac518709"},{"introduced":"51c6d3819be75d9587942242cdec709bc9934321"},{"fixed":"a82706b54052df26826f33a8421145572689e6b5"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.7.29"},{"introduced":"2.8.0"},{"fixed":"2.9.19"},{"introduced":"2.10.0"},{"fixed":"2.11.18"},{"introduced":"2.12.0"},{"fixed":"2.12.14"},{"introduced":"2.13.0"},{"fixed":"2.13.10"},{"introduced":"2.14.0"},{"fixed":"2.14.2"}]}}],"versions":["v2.14.1","v2.12.13","v2.11.17","v2.13.9","v2.7.28","2.9.18","v2.11.16","v2.14.0","v2.13.8","v2.11.15","v2.12.12","2.9.17","v2.7.27","v2.7.26","v2.13.7","v2.11.14","v2.12.11","2.9.16","v2.13.6","v2.7.25","2.9.15","v2.12.10","v2.11.13","v2.13.5","2.9.14","v2.7.24","v2.12.9","v2.13.4","v2.11.12","v2.9.13","2.9.13","v2.7.23","v2.11.11","v2.12.8","v2.13.3","v2.7.22","2.9.12","v2.11.10","v2.12.7","v2.13.2","2.9.11","v2.13.1","v2.12.6","v2.11.9","v2.7.21","v2.13.0","v2.12.5","v2.7.20","v2.11.8","v2.12.4","2.12.3","2.11.7","2.7.19","2.12.2","2.12.1","2.9.10","2.11.6","2.7.18","2.12.0","2.11.5","2.9.9","2.7.17","2.9.8","2.11.4","2.7.16","2.9.7","2.7.15","2.11.3","2.11.2","2.11.1","2.9.6","2.7.14","2.11.0","2.7.13","2.9.5","2.7.12","2.9.4","2.9.3","2.7.11","2.9.2","2.7.10","2.9.1","2.7.9","2.9.0","2.7.8","2.7.7","2.7.6","2.7.5","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0","1.5.0-rc1","1.4.0-rc1","1.2.0","1.2.0-rc1","1.0.0-rc2","1.0.0-rc1","080-preview-3","080-preview-2","080-preview-1","0.7.1","0.7.0","0.6.0","0.5.1","0.5.0","0.5.0-rc2","0.5.0-rc1","0.4.0","0.4.0-rc2","0.4.0-rc1","0.3.2","0.3.2-rc2","0.3.1","0.3.0","0.3.0-rc2","0.3.0-rc1","0.2.3-rc4","0.2.2","0.2.2-rc1","0.2.1","0.2.0","0.2.0-rc1","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18674.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N"}]}