ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security1

HashiCorp security advisory (AV26-910)

lowAdvisoryimportance 25
AI summary · glm-5.3-flash

Canada's Cyber Centre warns HashiCorp Consul and consul-template have authorization bypass and information disclosure flaws, urging users to apply available updates.

Advisory AV26-910 relays HashiCorp security advisories HCSEC-2026-34, HCSEC-2026-37 and HCSEC-2026-38 covering Consul and consul-template. Consul has an authorization bypass in the catalog node-write path and another in the Connect service mesh, while consul-template has an information disclosure issue in error handling. Fixed versions include Consul 2.0.4, Consul Enterprise 1.21.18 and consul-template 0.43.0. The Cyber Centre encourages users and administrators to review the linked advisories and apply updates.

  • Consul affected by two authorization bypasses: catalog node-write path and Connect service mesh.
  • consul-template information disclosure flaw stems from error handling before version 0.43.0.
  • Fixed releases include Consul 2.0.4, Consul Enterprise 1.21.18 and consul-template 0.43.0.
Full article107 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-910
Date: September 11, 2026

As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products:

  • Consul
    • Prior to 2.0.4
  • Consul Enterprise
    • 1.0 Prior to 1.21.18
    • 21.0 Prior to 1.21.18
    • 9.0 Prior to 1.21.18
  • consul-template
    • Prior to 0.43.0

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-910