{"id":"CVE-2026-18679","summary":"Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured","details":"When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection.\n\n\n\nAn on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.","aliases":["CVE-2026-52724","GHSA-wvmp-6r4v-j6cv","GO-2026-6013"],"modified":"2026-08-15T11:30:52.031829338Z","published":"2026-08-12T18:52:31.146Z","database_specific":{"cna_assigner":"Kong","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18679.json"},"references":[{"type":"ADVISORY","url":"https://developer.konghq.com/mesh/changelog/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18679.json"},{"type":"ADVISORY","url":"https://github.com/kumahq/kuma/security/advisories/GHSA-wvmp-6r4v-j6cv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18679"},{"type":"FIX","url":"https://github.com/kumahq/kuma/pull/16777"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kumahq/kuma","events":[{"introduced":"0"},{"fixed":"90c4dfdd7b5b67db087baca61d04ea8a4712ff2e"},{"introduced":"1110a0305eec00f1b2fd7482d6df4f3dd6a9d78e"},{"fixed":"2955869905710384ac686ab651d19953fc85e779"},{"introduced":"fed2256136e694d2a5deedb2490d382ee280fbbe"},{"fixed":"00ea5e4a54e2ca09b05d95f73e025d40d6f70c29"},{"introduced":"6b4779917a9f9f9a73ef959a22e243b9a14b4ba1"},{"fixed":"4bd8f7f6f9ad72b703be5fab2ead97dd09685d6b"},{"introduced":"99bb946e09bcdf7f7e6c1275c8bf14206db77274"},{"fixed":"744bfbb76ce474f568a10a88a6974c2b4db98bcd"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.7.26"},{"introduced":"2.8.0"},{"fixed":"2.9.16"},{"introduced":"2.10.0"},{"fixed":"2.11.14"},{"introduced":"2.12.0"},{"fixed":"2.12.11"},{"introduced":"2.13.0"},{"fixed":"2.13.7"}]}}],"versions":["v2.13.6","v2.7.25","2.9.15","v2.12.10","v2.11.13","v2.13.5","2.9.14","v2.7.24","v2.12.9","v2.13.4","v2.11.12","v2.9.13","2.9.13","v2.7.23","v2.11.11","v2.12.8","v2.13.3","v2.7.22","2.9.12","v2.11.10","v2.12.7","v2.13.2","2.9.11","v2.13.1","v2.12.6","v2.11.9","v2.7.21","v2.13.0","v2.12.5","v2.7.20","v2.11.8","v2.12.4","2.12.3","2.11.7","2.7.19","2.12.2","2.12.1","2.9.10","2.11.6","2.7.18","2.12.0","2.11.5","2.9.9","2.7.17","2.9.8","2.11.4","2.7.16","2.9.7","2.7.15","2.11.3","2.11.2","2.11.1","2.9.6","2.7.14","2.11.0","2.7.13","2.9.5","2.7.12","2.9.4","2.9.3","2.7.11","2.9.2","2.7.10","2.9.1","2.7.9","2.9.0","2.7.8","2.7.7","2.7.6","2.7.5","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0","1.5.0-rc1","1.4.0-rc1","1.2.0","1.2.0-rc1","1.0.0-rc2","1.0.0-rc1","080-preview-3","080-preview-2","080-preview-1","0.7.1","0.7.0","0.6.0","0.5.1","0.5.0","0.5.0-rc2","0.5.0-rc1","0.4.0","0.4.0-rc2","0.4.0-rc1","0.3.2","0.3.2-rc2","0.3.1","0.3.0","0.3.0-rc2","0.3.0-rc1","0.2.3-rc4","0.2.2","0.2.2-rc1","0.2.1","0.2.0","0.2.0-rc1","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18679.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"}]}