
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87106 is a denial-of-service vulnerability in the native RPC listener of HashiCorp Consul and Consul Enterprise that allows an authenticated client to exhaust server memory before ACL authorization is evaluated. An attacker who can complete the internal RPC mutual TLS (mTLS) handshake may exploit this issue without possessing a valid ACL token. Affected versions span from 1.21.0 up to (but not including) 2.0.4 for both Consul and Consul Enterprise. The vulnerability was published on September 10, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, HashiCorp).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption): the native RPC listener allocates memory in response to incoming requests before ACL authorization is checked, allowing a client to drive unbounded memory growth. An attacker must first complete the internal RPC mTLS handshake — establishing that they have network access and a valid TLS client certificate — but does not need a valid ACL token to trigger the memory exhaustion. Because authorization is evaluated after resource allocation, the access control mechanism provides no protection against this pre-authorization resource drain (GitHub Advisory, HashiCorp).
Successful exploitation causes the Consul server process to exhaust available memory, rendering the service unavailable and disrupting service mesh operations, service discovery, and configuration management for all dependent workloads. There is no confidentiality or integrity impact — the vulnerability is limited to availability. In environments where Consul is a critical infrastructure component, a sustained attack could cause cascading failures across services relying on Consul for health checking and routing (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.235%, placing it in the 15th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment indicates the vulnerability is not automatable and has no known exploitation. No threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
HashiCorp has released patched versions addressing this vulnerability: Consul 2.0.4 (open source) and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Upgrading to one of these versions is the recommended remediation. As an interim workaround, restrict network access to the native RPC listener (port 8300) to only trusted and known Consul agents and clients using firewall rules or network segmentation. Additionally, monitor server memory consumption for anomalous growth patterns that may indicate exploitation attempts (GitHub Advisory, HashiCorp).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."