
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2808 is an arbitrary file read vulnerability in HashiCorp Consul and Consul Enterprise affecting versions 1.18.20 through 1.21.10 and 1.22.4, when configured with Kubernetes authentication. The vulnerability was published on March 12, 2026, and is classified as CWE-59 (Improper Link Resolution Before File Access). It carries a CVSS v3.1 base score of 6.8 (Medium severity) with a changed scope, indicating impact can extend beyond the vulnerable component (Red Hat Advisory, Red Hat Bugzilla, HashiCorp Advisory).
The root cause is improper link resolution before file access (CWE-59), which manifests specifically when Consul is configured to use the Kubernetes (Vault) authentication provider. An attacker with high privileges can exploit this flaw over the network — without user interaction — to read arbitrary files from the host system by manipulating file path resolution, potentially via symlink-style attacks (CAPEC-132). The vulnerability requires the Kubernetes authentication method to be enabled in Consul's configuration, limiting the attack surface to deployments using this specific auth provider (HashiCorp Advisory, Red Hat Bugzilla).
Successful exploitation allows a privileged network attacker to read arbitrary files from affected Consul instances, resulting in high confidentiality impact with no integrity or availability impact. The changed scope in the CVSS vector indicates that sensitive files outside the Consul component itself — such as service account tokens, TLS certificates, or configuration secrets — may be disclosed. This could facilitate lateral movement or privilege escalation within a Kubernetes-integrated environment by exposing credentials or other sensitive material (Red Hat Advisory, HashiCorp Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.059%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges, which further limits the practical attack surface (Red Hat Advisory, HashiCorp Advisory).
/var/run/secrets/kubernetes.io/, TLS certificate directories, or /etc/) during Kubernetes authentication operations.HashiCorp has released patched versions addressing this vulnerability: Consul and Consul Enterprise 1.18.21, 1.21.11, and 1.22.5. Organizations should upgrade to the appropriate fixed version based on their current deployment. As an interim measure, restricting network access to Consul instances and limiting high-privilege account access can reduce exposure. Deployments not using Kubernetes authentication are not affected and do not require immediate action (HashiCorp Advisory, Red Hat Bugzilla).
The vulnerability was assigned and disclosed by HashiCorp as security advisory HCSEC-2026-02. Red Hat tracked it via Bugzilla (Bug 2446879) and published a corresponding CVE advisory. The ENISA European Vulnerability Database catalogued it as EUVD-2026-11487. Detection signatures have been published by Tenable (Nessus plugins 300552, 302002, 315290) and Qualys (detection ID 761789), and the vulnerability was noted in the openSUSE security announce mailing list, indicating broad awareness across the security community (HashiCorp Advisory, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."