CVE-2026-2808
Consul vulnerability analysis and mitigation

Overview

CVE-2026-2808 is an arbitrary file read vulnerability in HashiCorp Consul and Consul Enterprise affecting versions 1.18.20 through 1.21.10 and 1.22.4, when configured with Kubernetes authentication. The vulnerability was published on March 12, 2026, and is classified as CWE-59 (Improper Link Resolution Before File Access). It carries a CVSS v3.1 base score of 6.8 (Medium severity) with a changed scope, indicating impact can extend beyond the vulnerable component (Red Hat Advisory, Red Hat Bugzilla, HashiCorp Advisory).

Technical details

The root cause is improper link resolution before file access (CWE-59), which manifests specifically when Consul is configured to use the Kubernetes (Vault) authentication provider. An attacker with high privileges can exploit this flaw over the network — without user interaction — to read arbitrary files from the host system by manipulating file path resolution, potentially via symlink-style attacks (CAPEC-132). The vulnerability requires the Kubernetes authentication method to be enabled in Consul's configuration, limiting the attack surface to deployments using this specific auth provider (HashiCorp Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a privileged network attacker to read arbitrary files from affected Consul instances, resulting in high confidentiality impact with no integrity or availability impact. The changed scope in the CVSS vector indicates that sensitive files outside the Consul component itself — such as service account tokens, TLS certificates, or configuration secrets — may be disclosed. This could facilitate lateral movement or privilege escalation within a Kubernetes-integrated environment by exposing credentials or other sensitive material (Red Hat Advisory, HashiCorp Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.059%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges, which further limits the practical attack surface (Red Hat Advisory, HashiCorp Advisory).

Indicators of compromise

  • Logs: Unusual or unexpected file access entries in Consul server logs, particularly referencing sensitive paths (e.g., /var/run/secrets/kubernetes.io/, TLS certificate directories, or /etc/) during Kubernetes authentication operations.
  • Network: Anomalous high-privilege API calls to Consul endpoints associated with the Kubernetes auth provider from unexpected source IPs.
  • File System: Evidence of symlink creation or modification in directories accessible to the Consul process, particularly in paths related to Kubernetes service account token mounts.

Mitigation and workarounds

HashiCorp has released patched versions addressing this vulnerability: Consul and Consul Enterprise 1.18.21, 1.21.11, and 1.22.5. Organizations should upgrade to the appropriate fixed version based on their current deployment. As an interim measure, restricting network access to Consul instances and limiting high-privilege account access can reduce exposure. Deployments not using Kubernetes authentication are not affected and do not require immediate action (HashiCorp Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was assigned and disclosed by HashiCorp as security advisory HCSEC-2026-02. Red Hat tracked it via Bugzilla (Bug 2446879) and published a corresponding CVE advisory. The ENISA European Vulnerability Database catalogued it as EUVD-2026-11487. Detection signatures have been published by Tenable (Nessus plugins 300552, 302002, 315290) and Qualys (detection ID 761789), and the vulnerability was noted in the openSUSE security announce mailing list, indicating broad awareness across the security community (HashiCorp Advisory, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Consul vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19017MEDIUM6.8
  • Consul logoConsul
  • consul
NoYesAug 07, 2026
CVE-2026-19113MEDIUM5.3
  • Consul logoConsul
  • consul
NoYesAug 07, 2026
CVE-2026-19015MEDIUM5.3
  • Consul logoConsul
  • cpe:2.3:a:hashicorp:consul
NoYesAug 07, 2026
CVE-2026-19014MEDIUM4.3
  • Consul logoConsul
  • consul
NoYesAug 07, 2026
CVE-2026-19016MEDIUM4.2
  • Consul logoConsul
  • consul
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management