Impact
In Kong Mesh running in universal mode, a dataplane token that is not bound to a workload can register with any kuma.io/workload value when the MeshIdentity’s SPIFFE ID path template derives from that label. This flaw allows an attacker to obtain the SPIFFE identity of an arbitrary workload, effectively bypassing authentication and potentially allowing unauthorized access to services that rely on SPIFFE trust relationships.
Affected Systems
The vulnerability affects Kong Mesh versions prior to 2.13.10 for the 2.13.x line and prior to 2.14.2 for the 2.14.x line. Any installation using universal mode with MeshIdentity configurations that derive the SPIFFE path from the kuma.io/workload label is impacted.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack vector is internal to the cluster or via network paths that can reach the dataplane authentication endpoint. Authenticating a dataplane requires that a service account or token can reach the Kuma control‑plane. No specific credential or elevation requirements are stated, but the vulnerability allows the attacker to impersonate any workload identity once the attacker controls or creates a compliant dataplane token.
OpenCVE Enrichment