CVE-2026-87090
Consul: catalog node-write authorization bypass allows node identity takeover
Technology
HashiCorp Consul
CVSS Score
8.3 / 10.0
Affected Versions
Consul and Consul Enterprise up to 2.0.3
Upstream Fix
2.0.4; Enterprise 1.21.18, 1.22.12
Published
September 10, 2026
OSSeva Coverage
Fixed upstream
Description
The catalog node-registration endpoint did not check that a token had permission over every node a write could affect. A caller with node:write on any single node, who knows the node ID of a node they do not control, can delete that node's catalog registration with its services and health checks and take over its identity. Deployments without ACLs, or where every operator already holds unrestricted node:write, are not affected. The score is HashiCorp's as the CNA; NVD has not analysed the record.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise up to 2.0.3, you need this patch. Book a discovery call to get covered.