Description
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Consul Community Edition and Consul Enterprise versions 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service that can be triggered by writing a malicious service-router configuration entry. The flaw allows an authorized user with config‑entry write permission to cause an agent to exit unexpectedly, effectively crashing the Consul server. The vulnerability is limited to configurations that perform an Enterprise‑to‑Community Edition downgrade, and requires valid authentication and write access to configuration entries. The impact is localized to availability; confidentiality and integrity are not directly compromised.

Affected Systems

HashiCorp Consul Community Edition versions 1.18.0 to 2.0.2 and HashiCorp Consul Enterprise versions 1.18.0 through 2.0.2 (pre‑2.0.3). The vulnerable path exists for all these releases. The advisory explicitly lists the affected product families and the ranges that contain the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, meaning no publicly known exploitation probability is provided, but the weakness involves a drop‑in agent crash that is straightforward to trigger once the necessary permission is held. The issue is not yet in the CISA KEV catalog, suggesting it has not been widely abused yet. The most likely attack vector is an internal attacker or compromised service account with config‑entry write rights attempting to disrupt service availability by inserting a harmful configuration entry.

Generated by OpenCVE AI on August 7, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Consul 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3, which contain the fix.
  • Restrict config‑entry write permissions to trusted users only and validate permissions before applying changes.
  • Monitor Consul logs for unexpected agent exits or abnormal service‑router configuration changes and investigate any anomalies promptly.

Generated by OpenCVE AI on August 7, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-07T19:18:59.119Z

Reserved: 2026-08-05T20:21:09.285Z

Link: CVE-2026-19012

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:30:17Z

Weaknesses