Skip to content
HashiCorpCVE-2026-19016

HashiCorp Consul: path traversal

Medium4.2CVE-2026-19016 · Published Aug 7, 2026 · updated Aug 28, 2026

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Consul
Product
>= 1.19.1, < 2.0.32.0.3
Consul Enterprise
Product
>= 1.19.1, < 2.0.32.0.3
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Consul: denial of service
High7.5Aug 7
HashiCorp Consul: denial of service
Medium5.3Aug 7
HashiCorp Consul: resource exhaustion
Medium4.3Aug 7
HashiCorp Consul: resource exhaustion
Medium5.3Aug 7
HashiCorp Consul: arbitrary file read
Medium6.8Aug 7
HashiCorp Consul: denial of service
Medium5.3Aug 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.