
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19016 is an authorization bypass vulnerability in HashiCorp Consul Community Edition and Consul Enterprise that allows authenticated attackers to delete arbitrary sessions without the required session:write ACL permission. The flaw affects versions 1.19.1 through 2.0.2 of both editions and was published on August 7, 2026. It carries a CVSS v3.1 base score of 4.2 (Medium), reflecting the requirement for authentication and high attack complexity (GitHub Advisory, HashiCorp Forum).
The root cause is an improper access control enforcement issue (CWE-22 is assigned, though the vulnerability is functionally an authorization bypass) in Consul's transaction API: session deletion operations submitted via this API do not validate whether the caller holds the session:write ACL permission. An authenticated caller with network-level access to the Consul server RPC port can craft a transaction API request to delete any session, bypassing the intended ACL enforcement. Exploitation requires authentication and network access to the RPC port, making it a medium-complexity attack with no public proof-of-concept available (GitHub Advisory, HashiCorp Forum).
Successful exploitation allows an authenticated attacker to delete arbitrary Consul sessions without authorization, resulting in low integrity and low availability impacts. Session deletion can disrupt service mesh operations, invalidate distributed locks, and interfere with leader election or other session-dependent workflows within the Consul cluster. There is no confidentiality impact, and the scope is limited to the affected Consul instance without evidence of lateral movement potential (GitHub Advisory).
No public proof-of-concept exploit exists, and there is no evidence of in-the-wild exploitation as of the time of publication (HashiCorp Forum). The EPSS score is approximately 0.213% (12th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and direct network access to the Consul server RPC port, limiting the attacker pool (GitHub Advisory).
HashiCorp has released patches addressing this vulnerability. Users should upgrade to Consul Community Edition 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3. As an interim workaround, restrict network access to the Consul server RPC port to trusted hosts only using firewall rules or network segmentation. Additionally, monitor and audit session deletion operations in Consul logs for unauthorized activity (HashiCorp Forum, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."