Skip to content
HashiCorpCVE-2026-88021

Consul and Consul Enterprise are vulnerable to an authorization bypass in the...

High7.1CVE-2026-88021 · Published Sep 10, 2026

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Consul
Product
>= 1.9.0, < 2.0.42.0.4
Consul Enterprise
Product
>= 1.9.0, < 2.0.42.0.4
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Shared library: privilege escalation
Medium6.7Sep 15
HashiCorp Tooling: information disclosure
High7.7Sep 10
HashiCorp Consul: improper authorization
High8.3Sep 10
HashiCorp Consul: denial of service
Medium6.5Sep 10
HashiCorp Consul: improper authorization
Medium5.4Sep 10
HashiCorp Vault: insecure direct object reference
Medium6.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.