CVE-2026-88021
Consul: Connect intentions authorization bypass from unescaped characters in Envoy RBAC rules
Technology
HashiCorp Consul
CVSS Score
7.1 / 10.0
Affected Versions
Consul and Consul Enterprise 1.9.0 through 2.0.3
Upstream Fix
2.0.4; Enterprise 1.21.18, 1.22.12
Published
September 10, 2026
OSSeva Coverage
Fixed upstream
Description
When generating Envoy RBAC rules to enforce Connect intentions, Consul did not escape certain characters in service names, namespaces and partitions, so the rules could match a broader set of identities than intended and let a service reach a destination through an intention not created for it. It requires the service mesh with active intentions and catalog names that contain the affected characters. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.9.0 through 2.0.3, you need this patch. Book a discovery call to get covered.