Description
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass that occurs when a service proxy is configured with a custom public listener. The flaw allows an authenticated mesh workload to reach HTTP paths that are normally blocked by a path‑based deny intention, giving unauthorized access to restricted resources and potentially exposing sensitive data or allowing integrity violations. The vulnerability is categorized as CWE‑647, reflecting a flaw that grants access that should be denied.

Affected Systems

HashiCorp Consul Community Edition and HashiCorp Consul Enterprise, specifically versions 1.20.1 through 2.0.2, are impacted. The fix is included in Consul 2.0.3 and for Enterprise in versions 1.21.17, 1.22.11, and 2.0.3.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate risk level. EPSS data is currently unavailable, and the vulnerability is not listed in CISA’s known exploited vulnerabilities catalog. The likely attack vector involves configuring a custom public listener, so the exploitation requires administrative access to service proxy settings. Evidence shows that an authenticated mesh workload can bypass intention rules, highlighting the need for remediation before a broader threat surface emerges.

Generated by OpenCVE AI on August 7, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Consul to version 2.0.3 or later, or to Consul Enterprise 1.21.17, 1.22.11, or 2.0.3 which contain the fix.
  • Remove or disable any custom public listeners that are not required for normal operation until a patched version is deployed.
  • Re‑validate path‑based deny intentions and ensure mesh workloads are properly authenticated and authorized.

Generated by OpenCVE AI on August 7, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title L7 intention authorization bypass via custom public listener
Weaknesses CWE-647
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-07T19:20:13.639Z

Reserved: 2026-07-16T15:31:32.340Z

Link: CVE-2026-15970

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:30:17Z

Weaknesses
  • CWE-647

    Use of Non-Canonical URL Paths for Authorization Decisions