BIT-consul-2026-19016

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-19016.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-consul-2026-19016
Aliases
Published
2026-08-17T05:38:15.868Z
Modified
2026-08-17T08:00:16.506808200Z
Summary
Authorization bypass for session deletion in the transaction API
Details

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:community:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / consul

Package

Name
consul
Purl
pkg:bitnami/consul

Severity

  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.19.1
Fixed
2.0.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-19016.json"