CVE-2020-12797
Consul vulnerability analysis and mitigation

Overview

HashiCorp Consul and Consul Enterprise experienced a security vulnerability (CVE-2020-12797) where changes to legacy ACL token rules failed to propagate to secondary data centers. This vulnerability was introduced in version 1.4.0 and was fixed in versions 1.6.6 and 1.7.4, released on June 10, 2020 (HashiCorp Changelog).

Technical details

The vulnerability occurred in multi-datacenter Consul deployments where one datacenter acts as primary and others as secondary. When using legacy APIs to create or update legacy ACLs, an internal conversion process failed to compute a necessary field. As a result, when replicating legacy token updates, changes to a legacy ACL token's rules would not be propagated to secondary datacenters, potentially leaving them with outdated permissions (GitHub PR).

Impact

This vulnerability could lead to inconsistent access control enforcement across datacenters. If a token's permissions were reduced in the primary datacenter, the secondary datacenter might continue to allow access with the old permissions, potentially allowing unauthorized access to resources (GitHub PR).

Exploitability

The vulnerability affects environments using Consul in a multi-datacenter setup with legacy ACL tokens. It specifically impacts scenarios where token replication is enabled between primary and secondary datacenters, and where legacy ACL tokens are being modified (GitHub PR).

Mitigation and workarounds

The primary mitigation is to upgrade to Consul version 1.7.4 or 1.6.6. Alternative mitigations include either disabling token replication in secondary datacenters (which forces all token resolution against the primary DC), or deleting and recreating tokens instead of updating them in the primary datacenter (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related Consul vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19017MEDIUM6.8
  • Grafana logoGrafana
  • grafana
NoYesAug 07, 2026
CVE-2026-19113MEDIUM5.3
  • Consul logoConsul
  • consul
NoYesAug 07, 2026
CVE-2026-19015MEDIUM5.3
  • Consul logoConsul
  • cpe:2.3:a:hashicorp:consul
NoYesAug 07, 2026
CVE-2026-19014MEDIUM4.3
  • Grafana logoGrafana
  • grafana.src
NoYesAug 07, 2026
CVE-2026-19016MEDIUM4.2
  • Grafana logoGrafana
  • consul-fips-2.0
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management