Impact
Consul and Consul Enterprise are affected by an authorization bypass in the catalog node‑write path that lets an authenticated attacker delete another node’s catalog registration and assume its node identity. The flaw requires a token that grants node‑write permission for a single node name and knowledge of the target node’s ID. This weakness maps to CWE‑863 and enables an attacker with the appropriate credentials to compromise a node’s identity and potentially disrupt cluster operations.
Affected Systems
All versions of HashiCorp Consul and Consul Enterprise prior to the released patches are vulnerable. The vulnerability is fixed in Consul 2.0.4 and in Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Users running earlier releases should upgrade to these versions or later.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, and while an EPSS score is not available, the absence of listed KEV status does not diminish the risk. Exploitation requires possession of a node‑write token and the node ID, suggesting the likely attack vector is an authenticated internal actor or compromised node. Once exploited, the attacker can delete a node’s registration and impersonate that node, potentially leading to data integrity issues, service disruption, and unauthorized system access.
OpenCVE Enrichment