HashiCorpCVE-2026-16326
In consul-mcp-server
Critical10.0CVE-2026-16326 · Published Jul 29, 2026 · updated Jul 30, 2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Tooling Product | >= 0.1.0, < 0.1.4 | 0.1.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-488
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | HashiCorp Consul: denial of service | Medium5.3 | 2.0.3+1 more |
| Aug 7 | Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are... | Medium4.2 | 2.0.3+1 more |
| Jul 29 | HashiCorp Tooling: server-side request forgery | High8.6 | 0.1.4 |
| Jul 28 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant... | Critical10.0 | 1.1.0 |
| Jul 28 | HashiCorp Tooling: server-side request forgery | High8.6 | 1.1.0 |
| Jul 28 | HashiCorp Tooling: session fixation | High8.9 | 1.1.0 |