CVE-2026-16326

Source
https://cve.org/CVERecord?id=CVE-2026-16326
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16326.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16326
Published
2026-07-29T18:40:08.796Z
Modified
2026-08-01T03:32:56.590802357Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Details

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-488"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16326.json"
}
References

Affected packages

Git / github.com/hashicorp/consul-mcp-server

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul-mcp-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.1.0"
        },
        {
            "fixed": "0.1.4"
        }
    ]
}

Affected versions

v0.*
v0.1.2
v0.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16326.json"