HashiCorp security advisory (AV26-910)
Canada's Cyber Centre warns HashiCorp Consul and consul-template have authorization bypass and information disclosure flaws, urging users to apply available updates.
Advisory AV26-910 relays HashiCorp security advisories HCSEC-2026-34, HCSEC-2026-37 and HCSEC-2026-38 covering Consul and consul-template. Consul has an authorization bypass in the catalog node-write path and another in the Connect service mesh, while consul-template has an information disclosure issue in error handling. Fixed versions include Consul 2.0.4, Consul Enterprise 1.21.18 and consul-template 0.43.0. The Cyber Centre encourages users and administrators to review the linked advisories and apply updates.
- Consul affected by two authorization bypasses: catalog node-write path and Connect service mesh.
- consul-template information disclosure flaw stems from error handling before version 0.43.0.
- Fixed releases include Consul 2.0.4, Consul Enterprise 1.21.18 and consul-template 0.43.0.
Full article107 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-910
Date: September 11, 2026
As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products:
- Consul
- Prior to 2.0.4
- Consul Enterprise
- 1.0 Prior to 1.21.18
- 21.0 Prior to 1.21.18
- 9.0 Prior to 1.21.18
- consul-template
- Prior to 0.43.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path
- HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling
- HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh
- Security - HashiCorp Discuss
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/hashicorp-security-advisory-av26-910