PT-2026-93431 · Kong · Kong Enterprise Gateway
CVE-2026-14916
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kong API Gateway Enterprise (affected versions not specified)
Description
A JWT signature verification issue exists in Kong components that handle JWT validation for MCP OAuth2 or DataKit integrations. The system fails to properly validate whether the JWT signing algorithm is compatible with the key type used for verification. This allows an unauthenticated remote attacker to create a forged JWT that the system accepts as valid, resulting in an authentication bypass and potential compromise of confidentiality, integrity, and availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kong Enterprise Gateway