PT-2026-93431 · Kong · Kong Enterprise Gateway

CVE-2026-14916

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kong API Gateway Enterprise (affected versions not specified)
Description A JWT signature verification issue exists in Kong components that handle JWT validation for MCP OAuth2 or DataKit integrations. The system fails to properly validate whether the JWT signing algorithm is compatible with the key type used for verification. This allows an unauthenticated remote attacker to create a forged JWT that the system accepts as valid, resulting in an authentication bypass and potential compromise of confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14916

Affected Products

Kong Enterprise Gateway