Description
A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification.



As a result, an unauthenticated remote attacker may be able to craft a forged JWT that is incorrectly accepted as valid, leading to authentication bypass and potential compromise of confidentiality, integrity, and availability.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass through forged JWTs
Action: Apply patch
AI Analysis

Impact

A JWT signature verification flaw in Kong API Gateway Enterprise allows an attacker to craft a token that bypasses algorithm checks, leading to unauthorized access and potential loss of confidentiality, integrity, and availability.

Affected Systems

Kong API Gateway Enterprise components that perform JWT validation for MCP OAuth2 or DataKit integrations are affected. The fault lies in how the signing algorithm is verified against the verification key, and are not specified in the advisory.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at the present time. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated remote attacker can target services that accept JWTs, and if the attacker discovers the mismatch between the declared algorithm and the key type, they can forge a token that is incorrectly accepted, breaching authentication. The attack vector is inferred to be remote over any network interface that processes JWTs.

Generated by OpenCVE AI on September 18, 2026 at 09:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Kong Enterprise Gateway release that includes the fix for the JWT algorithm validation issue.
  • Configure JWT validation to explicitly reject tokens whose signing algorithm does not match the verification key type and enable only trusted algorithms.
  • Apply additional logging and alerting on authentication attempts that succeed without expected credentials to detect premature bypasses.

Generated by OpenCVE AI on September 18, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Kong
Kong kong Enterprise Gateway
Vendors & Products Kong
Kong kong Enterprise Gateway

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an unauthenticated remote attacker may be able to craft a forged JWT that is incorrectly accepted as valid, leading to authentication bypass and potential compromise of confidentiality, integrity, and availability.
Title Kong API Gateway Enterprise: JWT Algorithm-Confusion
Weaknesses CWE-241
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Kong Kong Enterprise Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: Kong

Published:

Updated: 2026-09-16T13:26:46.569Z

Reserved: 2026-07-07T07:14:53.612Z

Link: CVE-2026-14916

cve-icon Vulnrichment

Updated: 2026-09-16T13:26:43.516Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T11:16:40.503

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-14916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses
  • CWE-241

    Improper Handling of Unexpected Data Type