Consul 和 Consul Enterprise 在 Connect 服务网格中存在一个授权绕过漏洞,可能导致服务访问其未被授权访问的目标服务。在构建 Envoy RBAC 规则以执行 Connect 意图(intentions)时,Consul 未正确转义服务名称、命名空间和分区中的某些字符,导致生成的授权规则比预期匹配范围更广。该漏洞(CVE-2026-88021)已在 Consul 2.0.4 以及 Consul Enterprise 1.21.18、1.22.12 和 2.0.4 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Consul | 1.9.0< 2.0.4 |
affected |
| HashiCorp | Consul Enterprise | 1.9.0< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Consul | 1.9.0 ~ 2.0.4 | - |
|
| HashiCorp | Consul Enterprise | 1.9.0 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87090 | 8.3 HIGH | Consul vulnerable to an authorization bypass in the catalog node-write path |
| CVE-2026-87993 | 7.7 HIGH | Consul-template vulnerable to an information disclosure issue in error handling |
| CVE-2026-87106 | 6.5 MEDIUM | Consul vulnerable to a denial of service in the native RPC listener |
| CVE-2026-87107 | 5.4 MEDIUM | Consul vulnerable to an authorization bypass in the catalog deregistration path |
No comments yet