CVE-2026-2808
Consul: arbitrary file read through the Vault Connect CA provider's Kubernetes auth token_path
Technology
HashiCorp Consul
CVSS Score
6.8 / 10.0
Affected Versions
Consul Community Edition up to 1.22.4; Consul Enterprise up to 1.18.20, 1.21.10 and 1.22.4
Upstream Fix
Community 1.22.5; Enterprise 1.18.21, 1.21.11, 1.22.5
Published
March 12, 2026
OSSeva Coverage
Fixed upstream
Description
When the Connect CA provider uses Vault with the Kubernetes auth method, Consul reads a service account token from the file named in token_path. A privileged user with operator write permission can point token_path at any file on a Consul server, whose contents are then sent to Vault as the JWT. The fix restricts token reads to a defined set of directories. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul Community Edition up to 1.22.4; Consul Enterprise up to 1.18.20, 1.21.10 and 1.22.4, you need this patch. Book a discovery call to get covered.