CVE-2026-19017

Source
https://cve.org/CVERecord?id=CVE-2026-19017
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19017.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19017
Downstream
Published
2026-08-07T19:19:20.363Z
Modified
2026-08-09T03:45:55.403614528Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Consul vulnerable to partial arbitrary file read via Vault Connect CA provider
Details

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with operator:write permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-862"
    ],
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.18.21"
                },
                {
                    "fixed": "2.0.3"
                },
                {
                    "introduced": "1.18.21"
                },
                {
                    "fixed": "2.0.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19017.json"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "1.18.21"
        },
        {
            "fixed": "2.0.2"
        }
    ]
}

Affected versions

api/v1.*
api/v1.0.0
api/v1.0.1
api/v1.1.0
api/v1.10.0
api/v1.2.0
api/v1.32.1
api/v1.34.3
api/v1.4.0
ent-changelog-1.*
ent-changelog-1.11.0
ent-changelog-1.12.0
ent-changelog-1.13.0
ent-changelog-1.14.0
ent-changelog-1.15.0
ent-changelog-1.15.19
ent-changelog-1.16.0
ent-changelog-1.17.0
ent-changelog-1.18.0
ent-changelog-1.18.12
ent-changelog-1.18.13
ent-changelog-1.18.14
ent-changelog-1.18.15
ent-changelog-1.18.16
ent-changelog-1.18.17
ent-changelog-1.19.0
ent-changelog-1.19.10
ent-changelog-1.19.11
ent-changelog-1.19.12
ent-changelog-1.19.13
ent-changelog-1.20.0
ent-changelog-1.20.10
ent-changelog-1.20.11
ent-changelog-1.20.12
ent-changelog-1.20.13
ent-changelog-1.20.8
ent-changelog-1.20.9
ent-changelog-1.22.0
internal/v0.*
internal/v0.1.0
Other
list
proto-public/v0.*
proto-public/v0.1.0
proto-public/v0.1.1
sdk/v0.*
sdk/v0.1.0
sdk/v0.1.1
sdk/v0.18.0
sdk/v0.18.1
sdk/v0.2.0
sdk/v0.4.0
v0.*
v0.1.0
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.5.0
v0.5.0rc1
v0.5.1
v0.5.2
v0.6.0
v0.6.0-rc1
v0.6.0-rc2
v0.6.1
v0.6.3
v0.6.4
v0.6.4-rc3
v0.7.0
v0.7.0-rc1
v0.7.0-rc2
v0.7.1
v0.7.2
v0.7.2-rc1
v0.7.3
v0.7.4
v0.8.0
v0.8.0-rc1
v0.8.1
v0.8.2
v0.8.4
v0.8.5
v0.9.0
v0.9.0-rc1
v0.9.1
v0.9.2
v0.9.3
v0.9.3-rc1
v0.9.3-rc2
v1.*
v1.0.0
v1.0.0-beta1
v1.0.0-beta2
v1.0.1
v1.0.1-rc1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.4.0
v1.4.0-rc1
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.7.0
v1.7.0-beta1
v1.7.0-beta2
v1.7.0-beta3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19017.json"