When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection.
An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Konghq
Konghq kong Mesh |
|
| Vendors & Products |
Konghq
Konghq kong Mesh |
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy. | |
| Title | Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-08-13T14:45:35.957Z
Reserved: 2026-08-03T15:20:48.055Z
Link: CVE-2026-18679
Updated: 2026-08-13T14:45:33.225Z
Status : Received
Published: 2026-08-12T20:17:41.957
Modified: 2026-08-13T15:19:36.460
Link: CVE-2026-18679
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:48:04Z