Arbitrary File Read Vulnerability in HashiCorp Consul on Kubernetes
CVE-2026-2808
6.8MEDIUM
What is CVE-2026-2808?
HashiCorp Consul and Consul Enterprise versions 1.18.20 through 1.21.10 and 1.22.4 are susceptible to an arbitrary file read vulnerability when configured with Kubernetes authentication. This issue allows unauthorized access to sensitive files, posing a security risk for users who deploy Consul in Kubernetes environments. Mitigations are available in updated versions—1.18.21, 1.21.11, and 1.22.5—ensuring users can secure their systems.
Affected Version(s)
Consul 64 bit 0 < 1.22.5
Consul Enterprise 64 bit 0 < 1.22.5