Impact
The vulnerability occurs on a Kong Mesh global control plane where resources received over the zone‑to‑global KDS sync are attributed to the in‑band, sender‑controlled ControlPlane.Identifier instead of the authenticated zone identity derived from the connection. An attacker who owns the credentials of any enrolled zone can therefore inject, attribute, and overwrite resources in another zone’s namespace, effectively bypassing cross‑zone isolation and enabling unauthorized resource manipulation across the mesh. This is rooted in improper authorization logic (CWE‑863) and related to ineffective validation of input (CWE‑345).
Affected Systems
The affected product is Kong Mesh from Kong Inc. All versions prior to the following patched releases are impacted: 2.7.29, 2.9.19, 2.11.18, 2.12.14, 2.13.10, and 2.14.2. Any deployment using Kong Mesh without upgrading to one of these versions remains vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates high severity, and while the EPSS score is not available, the lack of KEV listing means the vulnerability has not yet been confirmed as actively exploited in the wild. Exploitation requires an authenticated zone credential and access to the zone‑to‑global KDS sync endpoint, which many internal or network‑perimeter users possess. Because the attacker can supply the in‑band ControlPlane.Identifier arbitrarily, the attack can be performed over the network without privilege escalation, allowing widespread injection and overwrite of resources inside any target zone. Consequently the risk profile is high and the vulnerability should be remediated promptly.
OpenCVE Enrichment