ConsulGHSA-cpfq-66p2-336j
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
Medium6.8CVE-2026-2808 · Published Mar 12, 2026 · updated Mar 24, 2026
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.18.21 | 1.18.21 |
| >= 1.22.0-rc1, < 1.22.5 | 1.22.5 | |
| >= 1.19.0, < 1.21.11 | 1.21.11 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-59
- Also known as
- BIT-consul-2026-2808, CVE-2026-2808, GO-2026-4690
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 282025 | Consul key/value endpoint is vulnerable to denial of service | Medium6.5 | 1.22.0 |
| Oct 282025 | Consul event endpoint is vulnerable to denial of service | Medium6.5 | 1.22.0 |
| Oct 312024 | Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability | Medium8.3 | 1.20.1 |
| Oct 312024 | Hashicorp Consul Cross-site Scripting vulnerability | Medium6.1 | 1.20.0 |
| Oct 312024 | Hashicorp Consul Path Traversal vulnerability | High8.1 | 1.20.1 |
| Jan 312024 | Privilege Escalation in HashiCorp Consul | Medium6.5 | 1.6.10+2 more |