CVE-2026-18678

Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.


We have discovered 332 live websites that are affected by CVE-2026-18678.

Run a Free Instant Scan




Affected Software

Product  Kong
Category Miscellaneous
Vulnerable Domains332 live websites (34% of Kong install base)
Vulnerable Versions
  • from 0 through 2.7.26
  • from 2.8 through 2.9.16
  • from 2.10 through 2.11.14
  • from 2.12 through 2.12.11
  • from 2.13 through 2.13.7
Vulnerable Versions Count38 versions ( 58% of all versions)


Common Weakness Enumeration

CWE-295 Improper Certificate Validation



Details

  • Published - Aug 12, 2026
  • Updated - Aug 13, 2026

Website Distribution by Country

Number of websites using CVE-2026-18678
United States143 websites



China91 websites
Germany12 websites
GB12 websites
Netherlands10 websites
France9 websites
Brazil4 websites
Switzerland4 websites
Singapore4 websites

Website Distribution by TLD

Number of websites using CVE-2026-18678
.com155 websites
.cn18 websites
.net14 websites
.org11 websites
.io8 websites
.co8 websites
.de7 websites
.com.br5 websites
.com.cn5 websites
.nl5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18678

Top websites that are affected by CVE-2026-18678. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.***.tr Turkey**,***
*******.land GB**,***
************.org China**,***
*************.**.com China**,***
*********.fr United States***,***
**********.com United States***,***
***.****************.com China***,***
***********.com United States***,***
**************.com GB***,***
*******.*************.org United States***,***
See full domain list

FAQ

CVE-2026-18678 is Improper Certificate Validation in Kong
A total of 332 websites have been identified as vulnerable to CVE-2026-18678, based on global website indexing conducted by WebTechSurvey.
The Kong is affected by the CVE-2026-18678 vulnerability.
Kong versions up to 2.13.7 are vulnerable to CVE-2026-18678.
CVE-2026-18678 is resolved in version 2.13.7 of Kong.