CVE detail
CVE-2026-18674
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone. The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide. The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 9
- within the 30d window
- Peak daily
- 9
- highest bucket
Evidence
Source links by recency
9 source links · newest first
No excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PM- https://developer.konghq.com/mesh/changelog/developer.konghq.com
No excerpt available.
referencedeveloper.konghq.comAug 17, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-53512CVSS 9.1 · Critical
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_toke…
- CVE-2026-48781CVSS 9.9 · Critical
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using th…
- CVE-2026-47777CVSS 7.5 · High
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a…
- CVE-2026-41432CVSS 7.1 · High
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook han…
- CVE-2026-32597CVSS 7.5 · High
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token con…
- CVE-2025-59420CVSS 7.5 · High
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header p…