« Volver al listado

CVE-2026-18676

Estado: Pendiente de análisisMedia (5.1)—

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-18676",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-18676",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-13T14:50:34.609630Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "ACTIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
      "affectedData": [
        {
          "vendor": "Kong Inc.",
          "modules": [
            "kuma-cp"
          ],
          "product": "Kong Mesh",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.7.25",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.8.0",
              "lessThan": "2.9.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.10.0",
              "lessThan": "2.11.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.12.0",
              "lessThan": "2.12.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.13.0",
              "lessThan": "2.13.5",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-12T19:17:30.813",
  "references": [
    {
      "url": "https://developer.konghq.com/mesh/changelog/",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16416",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16423",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16424",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16425",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16426",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/pull/16427",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    },
    {
      "url": "https://github.com/kumahq/kuma/security/advisories/GHSA-3vcp-chfh-f6r2",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        },
        {
          "lang": "en",
          "value": "CWE-942"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material."
    }
  ],
  "lastModified": "2026-08-31T19:22:43.473",
  "sourceIdentifier": "02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"
}