CVE-2026-18677EPSS p23.9%
CVE-2026-18677CVE-2026-18677
Description
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Scoring
| EPSS | 0.31% probability of exploitation · percentile 23.9% · 2026-08-13T12:03:51Z |
| Last modified | 2026-08-13 |