Authorization Bypass in Consul and Consul Enterprise
CVE-2026-87090
8.3HIGH
What is CVE-2026-87090?
Consul and Consul Enterprise are subject to an authorization bypass vulnerability within the catalog node-write path. This flaw permits an authenticated attacker, who possesses a node-write permission token for a specific node, to delete the catalog registration of another node and assume its identity. If an attacker gains knowledge of the node ID of a node that they do not control, they can exploit this weakness to manipulate node registrations, leading to potential unauthorized actions within the Consul environment. Users are encouraged to upgrade to patched versions to mitigate this issue.
Affected Version(s)
Consul 64 bit 0.1.0 < 2.0.4
Consul Enterprise 64 bit 0.1.0 < 2.0.4
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Raphael Zanarelli.