Authorization Bypass Vulnerability in Consul by HashiCorp
CVE-2026-15970
4.2MEDIUM
What is CVE-2026-15970?
Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are susceptible to an authorization bypass in Layer 7 (L7) intentions. This occurs when a service proxy is deployed with a custom public listener, enabling unauthorized access for authenticated mesh workloads to HTTP paths that should be restricted by an intention-based deny rule. This misconfiguration poses significant security risks, highlighting the importance of validating service configurations to prevent unauthorized access. The issue is resolved in Consul 2.0.3 and Consul Enterprise versions 1.21.17, 1.22.11, and 2.0.3.
Affected Version(s)
Consul 64 bit 1.20.1 < 2.0.3
Consul Enterprise 64 bit 1.20.1 < 2.0.3