Authorization Bypass Vulnerability in HashiCorp Consul and Consul Enterprise
CVE-2026-87107

5.4MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
10 September 2026

What is CVE-2026-87107?

HashiCorp Consul and Consul Enterprise are affected by an authorization bypass vulnerability that occurs within the catalog deregistration path. This issue could allow attackers with permissions such as {{service:write}} or {{node:write}} to delete peer-imported catalog objects, including services, checks, and nodes from a peered cluster, without the necessary authority over the source cluster. This vulnerability highlights the importance of securing ACL tokens and properly managing service permissions to maintain system integrity.

Affected Version(s)

Consul 64 bit 1.21.0 < 2.0.4

Consul Enterprise 64 bit 1.21.0 < 2.0.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Yazdan Soltani.
.