Session Deletion Vulnerability in Consul Community and Enterprise Editions
CVE-2026-19016
4.2MEDIUM
What is CVE-2026-19016?
A vulnerability in Consul Community Edition and Consul Enterprise allows authenticated users with network access to delete sessions via the transaction API without proper session:write ACL permissions. This flaw exists in versions 1.19.1 through 2.0.2 and has been addressed in Consul 2.0.3 and Consul Enterprise versions 1.21.17, 1.22.11, and 2.0.3, ensuring secure session management.
Affected Version(s)
Consul 64 bit 1.19.1 < 2.0.3
Consul Enterprise 64 bit 1.19.1 < 2.0.3