Description
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Published: 2026-09-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

Consul and Consul Enterprise allow an ACL token with service:write or node:write authority to delete services, checks, or nodes that were imported from a peered cluster. This bypass removes the requirement for authority over the peer origin, enabling a local user with write permissions to remove catalog objects that were not originally created locally. The vulnerability is a classic Inadequate Authorization flaw (CWE-863).

Affected Systems

HashiCorp Consul version prior to 2.0.4 and HashiCorp Consul Enterprise versions prior to 1.21.18, 1.22.12 or 2.0.4 are susceptible. Any deployment of these software versions without the listed fixes is impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS is not available, so the exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. The likely attack vector is local: an attacker needs to be able to execute actions as a user on the same host as Consul and possess a token with write ACLs. By doing so, the attacker can delete imported catalog entries, compromising the integrity of the cluster’s service registry.

Generated by OpenCVE AI on September 10, 2026 at 22:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Consul 2.0.4 or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4 to apply the vendor fix.
  • Limit ACL tokens to the minimal set of permissions required for their role, avoiding service:write or node:write unless absolutely necessary.
  • Monitor changes to catalog services and nodes, and set up alerts for unexpected deletions.

Generated by OpenCVE AI on September 10, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Title Consul vulnerable to an authorization bypass in the catalog deregistration path
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-09-10T19:22:09.223Z

Reserved: 2026-09-08T20:24:18.555Z

Link: CVE-2026-87107

cve-icon Vulnrichment

Updated: 2026-09-10T19:22:02.716Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T19:17:37.413

Modified: 2026-09-10T20:17:29.083

Link: CVE-2026-87107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:15:17Z

Weaknesses