Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-2808

Consul: arbitrary file read through the Vault Connect CA provider's Kubernetes auth token_path

Technology

HashiCorp Consul

CVSS Score

6.8 / 10.0

Affected Versions

Consul Community Edition up to 1.22.4; Consul Enterprise up to 1.18.20, 1.21.10 and 1.22.4

Upstream Fix

Community 1.22.5; Enterprise 1.18.21, 1.21.11, 1.22.5

Published

March 12, 2026

OSSeva Coverage

Fixed upstream

Description

When the Connect CA provider uses Vault with the Kubernetes auth method, Consul reads a service account token from the file named in token_path. A privileged user with operator write permission can point token_path at any file on a Consul server, whose contents are then sent to Vault as the JWT. The fix restricts token reads to a defined set of directories. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul Community Edition up to 1.22.4; Consul Enterprise up to 1.18.20, 1.21.10 and 1.22.4, you need this patch. Book a discovery call to get covered.