ZeroHour

CVE-2026-88021

moderate

Authorization Bypass in HashiCorp Consul Connect Service Mesh Intentions

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

HashiCorp Consul and Consul Enterprise contain an authorization bypass (CWE-185) in the Connect service mesh, caused by improper escaping when Consul builds Envoy RBAC rules that enforce Connect intentions. When service names, namespaces, or partitions contain certain characters, the generated authorization rules match more broadly than intended, allowing a low-privileged service in the mesh to connect to a destination its intentions do not authorize (CVSS 3.1: 7.1, network vector, low privileges required, no user interaction). An attacker who controls or compromises a registered workload can thereby reach restricted services, with high confidentiality impact and low integrity impact per the CVSS score. Only deployments using the Connect service mesh with intentions are affected; the flaw is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. There is no public proof of concept, the issue is not in CISA KEV, and no exploitation is currently known.

What to do: Upgrade to Consul 2.0.4, or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4. In the meantime, review Connect intentions for services whose names, namespaces, or partitions contain special characters, inspect the Envoy RBAC rules Consul generates for over-broad matches, and audit east-west service logs for connections that should have been denied by intentions.

Affected
HashiCorp ConsulVersions prior to 2.0.4 (fixed in Consul 2.0.4)
HashiCorp Consul EnterpriseVersions prior to 1.21.18, 1.22.12, and 2.0.4 (fixed in Consul Enterprise 1.21.18, 1.22.12, and 2.0.4)
Estimated exposure
moderateon the order of tens of thousands of Consul clusters, with the affected subset limited to those running Connect service mesh with intentions — Consul is deployed across tens of thousands of organizations as part of the broad HashiCorp install base, but only clusters that use the Connect service mesh with intentions — and whose service names, namespaces, or partitions contain the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

Weakness
CWE-185
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.