An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Kong Mesh 2.14.2. In patched versions the readiness reporter serves only /ready; the Envoy admin API stays on the Unix domain socket, which is not reachable over the pod network.
Vendor Workaround
Restrict network access to port 9902 to trusted monitoring only, for example with a Kubernetes NetworkPolicy.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication. An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed. | |
| Title | Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication | |
| Weaknesses | CWE-200 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-08-12T18:20:33.205Z
Reserved: 2026-08-03T15:18:30.454Z
Link: CVE-2026-18673
No data.
No data.
No data.
OpenCVE Enrichment
No data.