CVE-2026-19016
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-19016 is an authorization bypass vulnerability in HashiCorp Consul Community Edition and Consul Enterprise that allows authenticated attackers to delete arbitrary sessions without the required session:write ACL permission. The flaw affects versions 1.19.1 through 2.0.2 of both editions and was published on August 7, 2026. It carries a CVSS v3.1 base score of 4.2 (Medium), reflecting the requirement for authentication and high attack complexity (GitHub Advisory, HashiCorp Forum).

Technical details

The root cause is an improper access control enforcement issue (CWE-22 is assigned, though the vulnerability is functionally an authorization bypass) in Consul's transaction API: session deletion operations submitted via this API do not validate whether the caller holds the session:write ACL permission. An authenticated caller with network-level access to the Consul server RPC port can craft a transaction API request to delete any session, bypassing the intended ACL enforcement. Exploitation requires authentication and network access to the RPC port, making it a medium-complexity attack with no public proof-of-concept available (GitHub Advisory, HashiCorp Forum).

Impact

Successful exploitation allows an authenticated attacker to delete arbitrary Consul sessions without authorization, resulting in low integrity and low availability impacts. Session deletion can disrupt service mesh operations, invalidate distributed locks, and interfere with leader election or other session-dependent workflows within the Consul cluster. There is no confidentiality impact, and the scope is limited to the affected Consul instance without evidence of lateral movement potential (GitHub Advisory).

Exploitability

No public proof-of-concept exploit exists, and there is no evidence of in-the-wild exploitation as of the time of publication (HashiCorp Forum). The EPSS score is approximately 0.213% (12th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and direct network access to the Consul server RPC port, limiting the attacker pool (GitHub Advisory).

Mitigation and workarounds

HashiCorp has released patches addressing this vulnerability. Users should upgrade to Consul Community Edition 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3. As an interim workaround, restrict network access to the Consul server RPC port to trusted hosts only using firewall rules or network segmentation. Additionally, monitor and audit session deletion operations in Consul logs for unauthorized activity (HashiCorp Forum, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • harbor-2.14
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • cluster-api-azure-controller-1.26
NoYesAug 13, 2026
CVE-2026-17183HIGH7.1
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 19, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • vsphere-csi-syncer-3.5
NoYesAug 13, 2026
CVE-2026-11817MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management