Impact
Kuma-dp disables TLS verification to the control plane when no CA is configured, allowing an attacker to intercept the authentication token sent over the insecure connection. By impersonating the control plane, the attacker can inject a forged bootstrap configuration and compromise the proxy’s integrity and confidentiality. The weakness is a TLS certificate validation flaw (CWE‑295).
Affected Systems
Kong Mesh from Kong Inc. The vulnerability applies to all releases prior to the patched versions: 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7. The 2.14 line was shipped after the fix and is unaffected.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity, and the lack of an EPSS entry suggests limited publicly known exploitation. Attackers with on‑path or network access can perform man‑in‑the‑middle attacks to capture the token and impersonate the control plane. Though not listed in the CISA KEV catalog, the combination of TLS verification bypass and sensitive token exposure makes the risk high for systems exposed to adversaries.
OpenCVE Enrichment