Description
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a privileged attacker who has `operator:write` permission to instruct Consul to read credential files located outside the intended scope. If succeeded, the attacker can receive these files, effectively exfiltrating sensitive secrets from the Consul server host. The flaw is caused by the Vault Connect CA provider when configured with JWT or AppRole authentication and is classified as a missing authorization weakness. The impact is the compromise of confidentiality and potential exposure of confidential data.

Affected Systems

HashiCorp Consul Community Edition and Consul Enterprise versions 1.18.21 through 2.0.2 are affected. The defect is resolved in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Risk and Exploitability

The CVSS score of 6.8 denotes a medium severity risk. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog. The attack requires an attacker who already possesses operator:write authority, which is typically granted to trusted administrators or privileged processes. An attacker with this privilege could exploit the flaw internally or via compromised credentials to read arbitrary files and transmit them back to the attacker. The exploitation path therefore relies on inadequate authorization controls rather than remote code execution.

Generated by OpenCVE AI on August 7, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Consul patch (v2.0.3 for Community Edition or v1.21.17/v1.22.11/v2.0.3 for Enterprise) to eliminate the file read flaw.
  • Re‑evaluate ACL policies to ensure that only trusted users receive the operator:write permission and closely monitor any grants of this privilege.
  • If immediate patching is not possible, disable the Vault Connect CA provider or revert to a different authentication method until the vulnerability is patched.

Generated by OpenCVE AI on August 7, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title Consul vulnerable to partial arbitrary file read via Vault Connect CA provider
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-07T19:19:20.363Z

Reserved: 2026-08-05T20:21:43.136Z

Link: CVE-2026-19017

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:30:17Z

Weaknesses