The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.
{
"cwe_ids": [
"CWE-346",
"CWE-942"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18676.json",
"cna_assigner": "Kong"
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.7.25"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.9.15"
},
{
"introduced": "2.10.0"
},
{
"fixed": "2.11.13"
},
{
"introduced": "2.12.0"
},
{
"fixed": "2.12.10"
},
{
"introduced": "2.13.0"
},
{
"fixed": "2.13.5"
}
]
}