CVE-2026-88021
moderateAuthorization Bypass in HashiCorp Consul Connect Service Mesh Intentions
HashiCorp Consul and Consul Enterprise contain an authorization bypass (CWE-185) in the Connect service mesh, caused by improper escaping when Consul builds Envoy RBAC rules that enforce Connect intentions. When service names, namespaces, or partitions contain certain characters, the generated authorization rules match more broadly than intended, allowing a low-privileged service in the mesh to connect to a destination its intentions do not authorize (CVSS 3.1: 7.1, network vector, low privileges required, no user interaction). An attacker who controls or compromises a registered workload can thereby reach restricted services, with high confidentiality impact and low integrity impact per the CVSS score. Only deployments using the Connect service mesh with intentions are affected; the flaw is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. There is no public proof of concept, the issue is not in CISA KEV, and no exploitation is currently known.
What to do: Upgrade to Consul 2.0.4, or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4. In the meantime, review Connect intentions for services whose names, namespaces, or partitions contain special characters, inspect the Envoy RBAC rules Consul generates for over-broad matches, and audit east-west service logs for connections that should have been denied by intentions.
| HashiCorp Consul | Versions prior to 2.0.4 (fixed in Consul 2.0.4) |
| HashiCorp Consul Enterprise | Versions prior to 1.21.18, 1.22.12, and 2.0.4 (fixed in Consul Enterprise 1.21.18, 1.22.12, and 2.0.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
- Weakness
- CWE-185
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.