{"id":"CVE-2026-18677","summary":"Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity","details":"In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.","aliases":["GHSA-744g-c785-x65q"],"modified":"2026-08-15T11:31:01.458342683Z","published":"2026-08-12T18:47:06.710Z","database_specific":{"cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18677.json","cna_assigner":"Kong"},"references":[{"type":"ADVISORY","url":"https://developer.konghq.com/mesh/changelog/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18677.json"},{"type":"ADVISORY","url":"https://github.com/kumahq/kuma/security/advisories/GHSA-744g-c785-x65q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18677"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17474"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17502"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/17503"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kumahq/kuma","events":[{"introduced":"99bb946e09bcdf7f7e6c1275c8bf14206db77274"},{"fixed":"b9b8c3f84ad8ff5fede09577439eb12cac518709"},{"introduced":"51c6d3819be75d9587942242cdec709bc9934321"},{"fixed":"a82706b54052df26826f33a8421145572689e6b5"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.13.0"},{"fixed":"2.13.10"},{"introduced":"2.14.0"},{"fixed":"2.14.2"}]}}],"versions":["v2.14.1","v2.13.9","v2.14.0","v2.13.8","v2.13.7","v2.13.6","v2.13.5","v2.13.4","v2.13.3","v2.13.2","v2.13.1","v2.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18677.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}