Kong API Gateway Enterprise: JWT Algorithm-Confusion
Summary
| CVE | CVE-2026-14916 |
|---|---|
| State | PUBLISHED |
| Assigner | Kong |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:16:40 UTC |
| Updated | 2026-09-18 19:07:38 UTC |
| Description | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an unauthenticated remote attacker may be able to craft a forged JWT that is incorrectly accepted as valid, leading to authentication bypass and potential compromise of confidentiality, integrity, and availability. |
Risk And Classification
Primary CVSS: v4.0 7.7 HIGH from 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.006680000 probability, percentile 0.500800000 (date 2026-09-21)
Problem Types: CWE-241 | CWE-241 CWE-241 Improper handling of unexpected data type
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb | Secondary | 7.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
NoneIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Kong | Kong Enteprise Gateway | affected 3.15.0.0 3.15.0.3 custom | Linux |
| CNA | Kong | Kong Enteprise Gateway | affected 3.14.0.0 3.14.0.12 custom | Linux |
| CNA | Kong | Kong Enteprise Gateway | affected 3.13.0.0 3.13.0.9 custom | Linux |
| CNA | Kong | Kong Enteprise Gateway | affected 3.12.0.0 3.12.0.10 custom | Linux |
| CNA | Kong | Kong Enteprise Gateway | affected 3.10.0.0 3.10.0.17 custom | Linux |
| CNA | Kong | Kong Enteprise Gateway | affected 3.4.0.0 3.4.3.29 custom | Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| developer.konghq.com/gateway/changelog | 02762ae7-200e-4b20-9b2b-a77d5b8fc4cb | developer.konghq.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.