CVE-2026-19017
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-19017 is a partial arbitrary file read vulnerability in HashiCorp Consul Community Edition and Consul Enterprise affecting versions 1.18.21 through 2.0.2. The flaw is triggered when Consul is configured to use the Vault Connect CA provider with JWT or AppRole authentication, allowing a privileged attacker with operator:write permission to direct Consul to read and forward credential files outside the intended scope. It was published on August 7, 2026, and carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory, HashiCorp Forum).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — Consul does not perform sufficient authorization checks when processing Vault Connect CA provider configuration requests, allowing the operator:write role to specify credential file paths beyond the intended scope. An attacker exploiting this vulnerability can craft a Consul CA provider configuration that references arbitrary files on the Consul server host, causing Consul to read and forward their contents. Exploitation requires network access to the Consul API and a valid account or token with operator:write privileges; no user interaction is needed. Feedly's CWE estimate also flags CWE-22 (Path Traversal) as a contributing factor, suggesting the file path handling lacks proper boundary enforcement (GitHub Advisory, HashiCorp Forum).

Impact

Successful exploitation results in high confidentiality impact with no integrity or availability impact — an attacker can exfiltrate sensitive credential files (e.g., Vault tokens, AppRole secret IDs, JWT keys) from the Consul server host filesystem. Because the scope is marked as "Changed," the impact extends beyond the Consul process itself to the underlying host's secrets, potentially enabling lateral movement into Vault or other integrated systems. There is no evidence of data modification or service disruption as a direct result of this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.33% (26th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires high privileges (operator:write), limiting the attacker pool to insiders or compromised privileged accounts (HashiCorp Forum).

Exploitation steps

  1. Reconnaissance: Identify a Consul deployment (Community Edition or Enterprise, versions 1.18.21–2.0.2) configured to use the Vault Connect CA provider with JWT or AppRole authentication. Confirm the target is reachable via the Consul HTTP API.
  2. Obtain privileged credentials: Acquire a Consul ACL token with operator:write permission — this may be achieved through credential theft, insider access, or compromise of a system already holding such a token.
  3. Craft malicious CA provider configuration: Construct a Consul Connect CA configuration payload that specifies a file path outside the intended credential scope (e.g., /etc/passwd, a Vault token file, or an AppRole secret ID file) as the credential source for the Vault Connect CA provider.
  4. Submit configuration via API: Use the Consul API endpoint (e.g., PUT /v1/connect/ca/configuration) with the crafted payload and the privileged token to instruct Consul to read the targeted file.
  5. Retrieve exfiltrated content: Observe the Consul response or subsequent CA provider behavior to capture the contents of the targeted credential file, enabling further access to Vault or other integrated systems (GitHub Advisory, HashiCorp Forum).

Indicators of compromise

  • Network: Unexpected or anomalous API calls to /v1/connect/ca/configuration (PUT) from unusual source IPs or at unusual times; outbound connections from the Consul server to unknown destinations following CA configuration changes.
  • Logs: Consul audit log entries showing operator:write operations on the Connect CA configuration endpoint with file paths referencing locations outside the standard Vault credential directory; repeated or scripted CA configuration update requests.
  • File System: Access timestamps updated on sensitive files (e.g., Vault token files, AppRole secret ID files, /etc/passwd) coinciding with Consul API activity, without corresponding legitimate administrative actions.
  • Process: Consul server process accessing files in unexpected directories as observed via OS-level file access auditing (e.g., auditd on Linux) (HashiCorp Forum).

Mitigation and workarounds

HashiCorp has released patches addressing this vulnerability: upgrade to Consul Community Edition 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3 (HashiCorp Forum). As an interim workaround if immediate patching is not possible: restrict operator:write ACL permissions to the minimum set of trusted users, and consider disabling or limiting use of the Vault Connect CA provider with JWT or AppRole authentication until the patch is applied. Review Consul audit logs for unauthorized CA configuration changes as a detection measure.

Community reactions

HashiCorp disclosed this vulnerability as part of a multi-vulnerability advisory (HCSEC-2026-25) published on their community forum on August 7, 2026 (HashiCorp Forum). A Tenable Nessus detection plugin (ID 333566) was released to identify vulnerable Consul instances (Tenable). No significant independent researcher commentary or broad social media discussion has been observed beyond standard vulnerability aggregator coverage.

Additional resources

  • HashiCorp Forum — Official HashiCorp security advisory (HCSEC-2026-25)
  • GitHub Advisory — GitHub Advisory Database entry (GHSA-jgv4-5fjv-3xp7)
  • Tenable — Nessus detection plugin (ID 333566)

SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • harbor-2.14
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • cluster-api-azure-controller-1.26
NoYesAug 13, 2026
CVE-2026-17183HIGH7.1
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 19, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • vsphere-csi-syncer-3.5
NoYesAug 13, 2026
CVE-2026-11817MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management