Description
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token.

Affected Systems

Affected products include HashiCorp Consul and HashiCorp Consul Enterprise. Vulnerable implementations are before Consul 2.0.4 and before Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. Because the EPSS score is not available and the request is not listed in CISA KEV, the likelihood of immediate exploitation cannot be determined from the provided data. The attack requires a client that can perform the internal RPC mTLS handshake, suggesting that network access to the native RPC listener by an authenticated user, or by a client that can complete the handshake without a valid ACL token, is sufficient to trigger the denial of service.

Generated by OpenCVE AI on September 10, 2026 at 22:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Consul to version 2.0.4 or later
  • Upgrade Consul Enterprise to 1.21.18, 1.22.12, or 2.0.4
  • If a patch is not immediately available, restrict access to the native RPC listener to trusted hosts or networks to prevent unauthenticated clients from initiating memory‑expending requests

Generated by OpenCVE AI on September 10, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Title Consul vulnerable to a denial of service in the native RPC listener
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-09-10T19:02:24.164Z

Reserved: 2026-09-08T20:19:26.410Z

Link: CVE-2026-87106

cve-icon Vulnrichment

Updated: 2026-09-10T19:02:19.884Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T19:17:37.293

Modified: 2026-09-10T19:45:14.210

Link: CVE-2026-87106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption