BIT-consul-2026-87107

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-87107.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-consul-2026-87107
Aliases
Published
2026-09-25T12:20:51Z
Modified
2026-09-25T14:15:15Z
Summary
Consul vulnerable to an authorization bypass in the catalog deregistration path
Details

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / consul

Package

Name
consul
Purl
pkg:bitnami/consul

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.21.0
Fixed
2.0.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-87107.json"