HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh
Bulletin ID: HCSEC-2026-37 Affected Products / Versions: Consul and Consul Enterprise 1.9.0 through 2.0.3. Fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4.
- Severity
- HighCVSS 3.1 · 7.1
- Fix
- Fixed in 1.21.18Fix recorded today
- Affected versions
- 1.9.0 to before 2.0.4
- Weakness
- CWE-185
- Exploit likelihood
- 0.24% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- Consul+1 more
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: partial
- EU ID
- EUVD-2026-75700ENISA vulnerability database
What to do
Update to 1.21.18 or later.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact Low Some data can be modified
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N Open in FIRST.org calculatorReferences
- hashicorp.com · security HashiCorp