ZeroHour

CVE-2026-87090

large

Authorization bypass in HashiCorp Consul catalog node-write allows node identity takeover

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

HashiCorp Consul and Consul Enterprise contain an incorrect-authorization flaw (CWE-863) in the catalog node-write path. An authenticated attacker holding a token with node-write permission on any single node name can delete another node's catalog registration and take over that node's identity, provided they are able to obtain the target node's node ID. Successful exploitation corrupts service catalog state, producing high integrity and availability impact (CVSS 3.1: 8.3, High). Users running affected versions of Consul or Consul Enterprise are affected, especially in multi-team or multi-tenant clusters where many node-scoped tokens exist. There is no evidence of active exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Upgrade to Consul 2.0.4, or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4. As interim mitigation, audit issued tokens for node-write rights, restrict grants to the nodes they are meant to manage, and limit disclosure of node IDs to untrusted parties. No in-the-wild exploitation or public PoC is known, but remediate promptly given the High severity rating.

Affected
HashiCorp Consulversions prior to 2.0.4 (fixed in 2.0.4)
HashiCorp Consul Enterprise1.21.x prior to 1.21.18, 1.22.x prior to 1.22.12, and 2.0.x prior to 2.0.4 (fixed in 1.21.18, 1.22.12, and 2.0.4)
Estimated exposure
largeorder of tens of thousands of deployed Consul clusters/organizations (estimate) — Consul is a widely adopted service-discovery and service-mesh layer across enterprise data centers and Kubernetes environments, so an order-of-magnitude estimate from adoption and deployment patterns, rather than a public scan count, is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

In the news

No ingested article mentions this CVE yet.