CVE-2026-88021
Consul vulnerable to an authorization bypass in the Connect service mesh
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
| CWE | CWE-185 |
| Vendor | hashicorp |
| Product | consul |
| Published | Sep 10, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for hashicorp consul
Be the first to know when new high vulnerabilities affecting hashicorp consul are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
HashiCorp / Consul
1.9.0 < 2.0.4
HashiCorp / Consul Enterprise
1.9.0 < 2.0.4
References
Credits
This issue was reported to HashiCorp by Đoàn Thành.