Skip to content
ConsulGHSA-ccw8-7688-vqx4

HashiCorp Consul Privilege Escalation Vulnerability

High8.8CVE-2021-37219 · Published Sep 8, 2021 · updated Sep 10, 2026

HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.10.1, < 1.10.21.10.2
>= 1.9.0, < 1.9.91.9.9
< 1.8.151.8.15
Details and references

More Consul advisories

All Consul
Advisory
Consul: missing authorization
Medium6.5Sep 8, 2021
Incorrect Authorization in HashiCorp Consul
Medium5.3Jul 28, 2021
HashiCorp Consul L7 deny intention results in an allow action
High7.5Jul 19, 2021
Hashicorp Consul Missing SSL Certificate Validation
High7.5Jul 19, 2021
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
Medium5.3Jun 23, 2021
Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.