Description
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Consul Community Edition and Consul Enterprise versions 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service that can be triggered by writing a malicious service‑router configuration entry. The flaw allows an authorized user with config‑entry write permission to cause an agent to exit unexpectedly, effectively crashing the Consul server. The vulnerability is limited to configurations that perform an Enterprise‑to‑Community Edition downgrade, and requires valid authentication and write access to configuration entries. The impact is localized to availability; confidentiality and integrity are not directly compromised.

Affected Systems

HashiCorp Consul Community Edition versions 1.18.0 to 2.0.2 and HashiCorp Consul Enterprise versions 1.18.0 through 2.0.2 (pre‑2.0.3). The vulnerable path exists for all these releases. The advisory explicitly lists the affected product families and the ranges that contain the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, but the weakness involves a drop‑in agent crash that is straightforward to trigger once the necessary permission is held. The issue is not yet in the CISA KEV catalog, suggesting it has not been widely abused yet. The most likely attack vector is an internal attacker or compromised service account with config‑entry write rights attempting to disrupt service availability by inserting a harmful configuration entry.

Generated by OpenCVE AI on August 13, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Consul 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3, which contain the fix.
  • Restrict config‑entry write permissions to trusted users only and validate permissions before applying changes.
  • Monitor Consul logs for unexpected agent exits or abnormal service‑router configuration changes and investigate any anomalies promptly.

Generated by OpenCVE AI on August 13, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-15
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-10T18:24:44.737Z

Reserved: 2026-08-05T20:21:09.285Z

Link: CVE-2026-19012

cve-icon Vulnrichment

Updated: 2026-08-10T17:45:26.188Z

cve-icon NVD

Status : Received

Published: 2026-08-07T20:16:50.143

Modified: 2026-08-10T19:17:29.297

Link: CVE-2026-19012

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-07T19:18:59Z

Links: CVE-2026-19012 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T14:15:05Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting

  • CWE-476

    NULL Pointer Dereference