Consul 和 Consul Enterprise 在目录(catalog)的节点写入路径中存在一个授权绕过漏洞,可能允许经过身份验证的攻击者删除其他节点的目录注册信息,并接管该节点的身份。如果攻击者拥有一个授予单个节点名称“节点写入”权限的令牌,并且能够获取到一个其无法控制的节点的节点 ID,就可以利用此漏洞。该漏洞(CVE-2026-87090)已在 Consul 2.0.4 以及 Consul Enterprise 1.21.18、1.22.12 和 2.0.4 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Consul | 0.1.0< 2.0.4 |
affected |
| HashiCorp | Consul Enterprise | 0.1.0< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Consul | 0.1.0 ~ 2.0.4 | - |
|
| HashiCorp | Consul Enterprise | 0.1.0 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87993 | 7.7 HIGH | Consul-template vulnerable to an information disclosure issue in error handling |
| CVE-2026-88021 | 7.5 HIGH | Consul vulnerable to an authorization bypass in the Connect service mesh |
| CVE-2026-87106 | 6.5 MEDIUM | Consul vulnerable to a denial of service in the native RPC listener |
| CVE-2026-87107 | 5.4 MEDIUM | Consul vulnerable to an authorization bypass in the catalog deregistration path |
No comments yet