Impact
The vulnerability allows an operator to configure kumactl with an HTTPS control plane profile without supplying a CA certificate. In that scenario, kumactl disables TLS certificate verification, sending API tokens over an unverified channel. An attacker positioned on the network path can intercept these tokens and authenticate to the control plane as the victim user, gaining unauthorized administrative access.
Affected Systems
The affected product is Kong Mesh, specifically all releases older than 2.7.26 on the 2.7 line, older than 2.9.16 on the 2.9 line, older than 2.11.14 on the 2.11 line, older than 2.12.11 on the 2.12 line, and older than 2.13.7 on the 2.13 line. The 2.14 line was released after the fix and is not impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a network-based interception; an adversary on the wire can capture the unverified API tokens and then impersonate the user to the control plane. Because TLS verification is disabled by default when no CA is supplied, the exploit does not require additional configuration beyond intercepting traffic between the operator and the control plane.
OpenCVE Enrichment