Answer in brief
CVE-2026-18679 records a Unknown severity vulnerability in Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured. The current sources do not mark it as known exploited. The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Kong Inc./Kong Meshgeneric | >=0 <2.7.26 || >=2.8.0 <2.9.16 || >=2.10.0 <2.11.14 || >=2.12.0 <2.12.11 || >=2.13.0 <2.13.7 | 2.7.26, 2.9.16, 2.11.14, 2.12.11, 2.13.7 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-18679 records a Unknown severity vulnerability in Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured. The current sources do not mark it as known exploited. The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Kong Inc./Kong Mesh (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Kong Inc./Kong Meshgeneric | >=0 <2.7.26 || >=2.8.0 <2.9.16 || >=2.10.0 <2.11.14 || >=2.12.0 <2.12.11 || >=2.13.0 <2.13.7 | 2.7.26, 2.9.16, 2.11.14, 2.12.11, 2.13.7 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
Quoted source text, attributed separately from HOL analysis.