๐Ÿ” CVE Alert

CVE-2026-2808

MEDIUM 6.8

Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CWE CWE-59
Vendor hashicorp
Product consul
Published Mar 11, 2026
Last Updated Mar 12, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp consul

Be the first to know when new medium vulnerabilities affecting hashicorp consul are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Consul
0 < 1.22.5
HashiCorp / Consul Enterprise
0 < 1.22.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2026-02-consul-vulnerable-to-arbitrary-file-reads-through-the-vault-kubernetes-authentication-provider/77232