Partial Arbitrary File Read Vulnerability in HashiCorp Consul Community and Enterprise Editions
CVE-2026-19017
6.8MEDIUM
What is CVE-2026-19017?
The vulnerability allows a malicious actor with operator:write permission to exploit Consul's configuration with the Vault Connect CA provider. This misconfiguration can lead to a partial arbitrary file read, enabling the attacker to access and exfiltrate sensitive credential files not intended for exposure. This presents a significant risk as it could compromise secret data stored within the Consul server environment. The issue affects both the Community and Enterprise versions of Consul as specified, and it has been patched in later releases.
Affected Version(s)
Consul 64 bit 1.18.21 < 2.0.3
Consul Enterprise 64 bit 1.18.21 < 2.0.3
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Kai Aizen / SnailSploit ("The Jailbreak Chef").