
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19017 is a partial arbitrary file read vulnerability in HashiCorp Consul Community Edition and Consul Enterprise affecting versions 1.18.21 through 2.0.2. The flaw is triggered when Consul is configured to use the Vault Connect CA provider with JWT or AppRole authentication, allowing a privileged attacker with operator:write permission to direct Consul to read and forward credential files outside the intended scope. It was published on August 7, 2026, and carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory, HashiCorp Forum).
The root cause is classified as CWE-862 (Missing Authorization) — Consul does not perform sufficient authorization checks when processing Vault Connect CA provider configuration requests, allowing the operator:write role to specify credential file paths beyond the intended scope. An attacker exploiting this vulnerability can craft a Consul CA provider configuration that references arbitrary files on the Consul server host, causing Consul to read and forward their contents. Exploitation requires network access to the Consul API and a valid account or token with operator:write privileges; no user interaction is needed. Feedly's CWE estimate also flags CWE-22 (Path Traversal) as a contributing factor, suggesting the file path handling lacks proper boundary enforcement (GitHub Advisory, HashiCorp Forum).
Successful exploitation results in high confidentiality impact with no integrity or availability impact — an attacker can exfiltrate sensitive credential files (e.g., Vault tokens, AppRole secret IDs, JWT keys) from the Consul server host filesystem. Because the scope is marked as "Changed," the impact extends beyond the Consul process itself to the underlying host's secrets, potentially enabling lateral movement into Vault or other integrated systems. There is no evidence of data modification or service disruption as a direct result of this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.33% (26th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires high privileges (operator:write), limiting the attacker pool to insiders or compromised privileged accounts (HashiCorp Forum).
operator:write permission — this may be achieved through credential theft, insider access, or compromise of a system already holding such a token./etc/passwd, a Vault token file, or an AppRole secret ID file) as the credential source for the Vault Connect CA provider.PUT /v1/connect/ca/configuration) with the crafted payload and the privileged token to instruct Consul to read the targeted file./v1/connect/ca/configuration (PUT) from unusual source IPs or at unusual times; outbound connections from the Consul server to unknown destinations following CA configuration changes.operator:write operations on the Connect CA configuration endpoint with file paths referencing locations outside the standard Vault credential directory; repeated or scripted CA configuration update requests./etc/passwd) coinciding with Consul API activity, without corresponding legitimate administrative actions.auditd on Linux) (HashiCorp Forum).HashiCorp has released patches addressing this vulnerability: upgrade to Consul Community Edition 2.0.3 or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3 (HashiCorp Forum). As an interim workaround if immediate patching is not possible: restrict operator:write ACL permissions to the minimum set of trusted users, and consider disabling or limiting use of the Vault Connect CA provider with JWT or AppRole authentication until the patch is applied. Review Consul audit logs for unauthorized CA configuration changes as a detection measure.
HashiCorp disclosed this vulnerability as part of a multi-vulnerability advisory (HCSEC-2026-25) published on their community forum on August 7, 2026 (HashiCorp Forum). A Tenable Nessus detection plugin (ID 333566) was released to identify vulnerable Consul instances (Tenable). No significant independent researcher commentary or broad social media discussion has been observed beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."