Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-19017

Consul: partial arbitrary file read through the Vault Connect CA provider with JWT or AppRole auth

Technology

HashiCorp Consul

CVSS Score

6.8 / 10.0

Affected Versions

Consul and Consul Enterprise 1.18.21 through 2.0.2

Upstream Fix

2.0.3; Enterprise 1.21.17, 1.22.11

Published

August 7, 2026

OSSeva Coverage

Fixed upstream

Description

The credential directory allowlist used by the Vault Connect CA provider's JWT and AppRole auth methods was broader than intended, so a caller with operator:write can make Consul read a credential file outside the intended scope and forward it to Vault. Deployments using the Kubernetes auth method, or not using the Vault CA provider, are not affected. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.18.21 through 2.0.2, you need this patch. Book a discovery call to get covered.