CVE-2026-19017
Consul: partial arbitrary file read through the Vault Connect CA provider with JWT or AppRole auth
Technology
HashiCorp Consul
CVSS Score
6.8 / 10.0
Affected Versions
Consul and Consul Enterprise 1.18.21 through 2.0.2
Upstream Fix
2.0.3; Enterprise 1.21.17, 1.22.11
Published
August 7, 2026
OSSeva Coverage
Fixed upstream
Description
The credential directory allowlist used by the Vault Connect CA provider's JWT and AppRole auth methods was broader than intended, so a caller with operator:write can make Consul read a credential file outside the intended scope and forward it to Vault. Deployments using the Kubernetes auth method, or not using the Vault CA provider, are not affected. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.18.21 through 2.0.2, you need this patch. Book a discovery call to get covered.