Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-87090

Consul: catalog node-write authorization bypass allows node identity takeover

Technology

HashiCorp Consul

CVSS Score

8.3 / 10.0

Affected Versions

Consul and Consul Enterprise up to 2.0.3

Upstream Fix

2.0.4; Enterprise 1.21.18, 1.22.12

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

The catalog node-registration endpoint did not check that a token had permission over every node a write could affect. A caller with node:write on any single node, who knows the node ID of a node they do not control, can delete that node's catalog registration with its services and health checks and take over its identity. Deployments without ACLs, or where every operator already holds unrestricted node:write, are not affected. The score is HashiCorp's as the CNA; NVD has not analysed the record.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise up to 2.0.3, you need this patch. Book a discovery call to get covered.