A vulnerability, which was classified as very critical, has been found in Kong Mesh up to 2.13.9/2.14.1. Affected by this issue is some unknown functionality of the component XDS authenticator. The manipulation leads to improper authentication.

This vulnerability is traded as CVE-2026-18677. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.