Description
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Published: 2026-09-10
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass – node identity takeover
Action: Immediate Patch
AI Analysis

Impact

Consul and Consul Enterprise are affected by an authorization bypass in the catalog node‑write path that lets an authenticated attacker delete another node’s catalog registration and assume its node identity. The flaw requires a token that grants node‑write permission for a single node name and knowledge of the target node’s ID. This weakness maps to CWE‑863 and enables an attacker with the appropriate credentials to compromise a node’s identity and potentially disrupt cluster operations.

Affected Systems

All versions of HashiCorp Consul and Consul Enterprise prior to the released patches are vulnerable. The vulnerability is fixed in Consul 2.0.4 and in Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Users running earlier releases should upgrade to these versions or later.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, and while an EPSS score is not available, the absence of listed KEV status does not diminish the risk. Exploitation requires possession of a node‑write token and the node ID, suggesting the likely attack vector is an authenticated internal actor or compromised node. Once exploited, the attacker can delete a node’s registration and impersonate that node, potentially leading to data integrity issues, service disruption, and unauthorized system access.

Generated by OpenCVE AI on September 10, 2026 at 22:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Consul 2.0.4 or later, or to Consul Enterprise 1.21.18, 1.22.12, or 2.0.4 to apply the patch
  • If upgrading is not immediately possible, revoke any node‑write tokens that are not strictly required, especially those that could access other nodes’ registrations
  • Apply the principle of least privilege by restricting node‑write permissions to only trusted nodes and ensure that node IDs are not exposed to unauthorized actors

Generated by OpenCVE AI on September 10, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Title Consul vulnerable to an authorization bypass in the catalog node-write path
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-09-10T19:02:58.403Z

Reserved: 2026-09-08T19:58:12.912Z

Link: CVE-2026-87090

cve-icon Vulnrichment

Updated: 2026-09-10T19:02:53.867Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T19:17:37.157

Modified: 2026-09-10T19:45:14.210

Link: CVE-2026-87090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:45:06Z

Weaknesses