CVE-2026-19016

Source
https://cve.org/CVERecord?id=CVE-2026-19016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19016
Downstream
Published
2026-08-07T19:18:08.980Z
Modified
2026-08-09T03:46:04.242112583Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Authorization bypass for session deletion in the transaction API
Details

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-22"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.19.1"
                },
                {
                    "fixed": "2.0.3"
                },
                {
                    "introduced": "1.19.1"
                },
                {
                    "fixed": "2.0.3"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19016.json"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "1.19.1"
        },
        {
            "fixed": "2.0.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19016.json"