HashiCorpCVE-2026-88021
Consul and Consul Enterprise are vulnerable to an authorization bypass in the...
High7.1CVE-2026-88021 · Published Sep 10, 2026
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Consul Product | >= 1.9.0, < 2.0.4 | 2.0.4 |
| Consul Enterprise Product | >= 1.9.0, < 2.0.4 | 2.0.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-185
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | HashiCorp Shared library: privilege escalation | Medium6.7 | 2.2.4 |
| Sep 10 | HashiCorp Tooling: information disclosure | High7.7 | 0.43.0 |
| Sep 10 | HashiCorp Consul: improper authorization | High8.3 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: denial of service | Medium6.5 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: improper authorization | Medium5.4 | 2.0.4+1 more |
| Aug 24 | HashiCorp Vault: insecure direct object reference | Medium6.8 | 2.0.4+1 more |