Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-88021

Consul: Connect intentions authorization bypass from unescaped characters in Envoy RBAC rules

Technology

HashiCorp Consul

CVSS Score

7.1 / 10.0

Affected Versions

Consul and Consul Enterprise 1.9.0 through 2.0.3

Upstream Fix

2.0.4; Enterprise 1.21.18, 1.22.12

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

When generating Envoy RBAC rules to enforce Connect intentions, Consul did not escape certain characters in service names, namespaces and partitions, so the rules could match a broader set of identities than intended and let a service reach a destination through an intention not created for it. It requires the service mesh with active intentions and catalog names that contain the affected characters. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.9.0 through 2.0.3, you need this patch. Book a discovery call to get covered.