Impact
Consul and Consul Enterprise allow an ACL token with service:write or node:write authority to delete services, checks, or nodes that were imported from a peered cluster. This bypass removes the requirement for authority over the peer origin, enabling a local user with write permissions to remove catalog objects that were not originally created locally. The vulnerability is a classic Inadequate Authorization flaw (CWE-863).
Affected Systems
HashiCorp Consul version prior to 2.0.4 and HashiCorp Consul Enterprise versions prior to 1.21.18, 1.22.12 or 2.0.4 are susceptible. Any deployment of these software versions without the listed fixes is impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is not available, so the exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. The likely attack vector is local: an attacker needs to be able to execute actions as a user on the same host as Consul and possess a token with write ACLs. By doing so, the attacker can delete imported catalog entries, compromising the integrity of the cluster’s service registry.
OpenCVE Enrichment