CVE-2026-19016

Source
https://cve.org/CVERecord?id=CVE-2026-19016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19016
Aliases
Downstream
Related
Published
2026-08-07T19:18:08Z
Modified
2026-08-30T03:30:38Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Authorization bypass for session deletion in the transaction API
Details

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19016.json"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.19.1"
        },
        {
            "fixed": "2.0.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19016.json"