A vulnerability classified as problematic has been found in Kong Kuma up to 2.7.24/2.9.14/2.11.12/2.12.9/2.13.4 . Affected is an unknown function of the component Control Plane . Performing a manipulation results in permissive cross-domain policy with untrusted domains. This vulnerability is reported as CVE-2026-18676 . The attack is possible to be carried out remotely. No exploit exists. It is recommended to upgrade the affected component.