Authorization Bypass Vulnerability in Consul by HashiCorp
CVE-2026-15970

4.2MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 August 2026

What is CVE-2026-15970?

Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are susceptible to an authorization bypass in Layer 7 (L7) intentions. This occurs when a service proxy is deployed with a custom public listener, enabling unauthorized access for authenticated mesh workloads to HTTP paths that should be restricted by an intention-based deny rule. This misconfiguration poses significant security risks, highlighting the importance of validating service configurations to prevent unauthorized access. The issue is resolved in Consul 2.0.3 and Consul Enterprise versions 1.21.17, 1.22.11, and 2.0.3.

Affected Version(s)

Consul 64 bit 1.20.1 < 2.0.3

Consul Enterprise 64 bit 1.20.1 < 2.0.3

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported by Erichen.
.