A vulnerability classified as problematic has been found in Kong Kuma up to 2.7.24/2.9.14/2.11.12/2.12.9/2.13.4. Affected is an unknown function of the component Control Plane. Performing a manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is reported as CVE-2026-18676. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.