CVE-2026-87090
largeAuthorization bypass in HashiCorp Consul catalog node-write allows node identity takeover
HashiCorp Consul and Consul Enterprise contain an incorrect-authorization flaw (CWE-863) in the catalog node-write path. An authenticated attacker holding a token with node-write permission on any single node name can delete another node's catalog registration and take over that node's identity, provided they are able to obtain the target node's node ID. Successful exploitation corrupts service catalog state, producing high integrity and availability impact (CVSS 3.1: 8.3, High). Users running affected versions of Consul or Consul Enterprise are affected, especially in multi-team or multi-tenant clusters where many node-scoped tokens exist. There is no evidence of active exploitation: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade to Consul 2.0.4, or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4. As interim mitigation, audit issued tokens for node-write rights, restrict grants to the nodes they are meant to manage, and limit disclosure of node IDs to untrusted parties. No in-the-wild exploitation or public PoC is known, but remediate promptly given the High severity rating.
| HashiCorp Consul | versions prior to 2.0.4 (fixed in 2.0.4) |
| HashiCorp Consul Enterprise | 1.21.x prior to 1.21.18, 1.22.x prior to 1.22.12, and 2.0.x prior to 2.0.4 (fixed in 1.21.18, 1.22.12, and 2.0.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.