Answer in brief
CVE-2026-18678 records a Unknown severity vulnerability in Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured. The current sources do not mark it as known exploited. The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Kong Inc./Kong Meshgeneric | >=0 <2.7.26 || >=2.8.0 <2.9.16 || >=2.10.0 <2.11.14 || >=2.12.0 <2.12.11 || >=2.13.0 <2.13.7 | 2.7.26, 2.9.16, 2.11.14, 2.12.11, 2.13.7 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-18678 records a Unknown severity vulnerability in Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured. The current sources do not mark it as known exploited. The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Kong Inc./Kong Meshgeneric | >=0 <2.7.26 || >=2.8.0 <2.9.16 || >=2.10.0 <2.11.14 || >=2.12.0 <2.12.11 || >=2.13.0 <2.13.7 | 2.7.26, 2.9.16, 2.11.14, 2.12.11, 2.13.7 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
Quoted source text, attributed separately from HOL analysis.