When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
We have discovered 332 live websites that are affected by CVE-2026-18678.
| Product | |
| Category | Miscellaneous |
| Vulnerable Domains | 332 live websites (34% of Kong install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 38 versions ( 58% of all versions) |
| 143 websites | |
| 91 websites | |
| 12 websites | |
| 12 websites | |
| 10 websites | |
| 9 websites | |
| 4 websites | |
| 4 websites | |
| 4 websites |
| .com | 155 websites |
| .cn | 18 websites |
| .net | 14 websites |
| .org | 11 websites |
| .io | 8 websites |
| .co | 8 websites |
| .de | 7 websites |
| .com.br | 5 websites |
| .com.cn | 5 websites |
| .nl | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.***.tr | **,*** | ||
| *******.land | **,*** | ||
| ************.org | **,*** | ||
| *************.**.com | **,*** | ||
| *********.fr | ***,*** | ||
| **********.com | ***,*** | ||
| ***.****************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| **************.com | ***,*** | ||
| *******.*************.org | ***,*** |
FAQ