CVE-2026-19017
Received Received - Intake

Partial Arbitrary File Read in Consul with Vault CA Provider

Vulnerability report for CVE-2026-19017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: HashiCorp Inc.

Description

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
hashicorp consul 1.18.21
hashicorp consul 2.0.2
hashicorp consul to 2.0.3 (inc)
hashicorp consul_enterprise 1.21.17
hashicorp consul_enterprise 1.22.11
hashicorp consul_enterprise 2.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Consul versions 1.18.21 through 2.0.2 have a flaw when using Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with write permissions could trick Consul into reading and sending credential files outside the intended scope, potentially exposing sensitive secrets from the server host.

Detection Guidance

Detecting this vulnerability requires checking if your Consul instance is running a vulnerable version and if the Vault Connect CA provider with JWT or AppRole authentication is configured. Verify Consul version with `consul version` and inspect configuration files for Vault CA provider settings. Look for unauthorized file access attempts in logs.

Impact Analysis

If exploited, this vulnerability could allow an attacker to steal sensitive secrets stored on the Consul server host, including credentials or other confidential data. This could lead to unauthorized access to systems or data.

Compliance Impact

This vulnerability may lead to the exfiltration of sensitive secrets from the Consul server host, which could include personal data or protected health information. Such unauthorized access could violate GDPR's data protection principles or HIPAA's security requirements for safeguarding sensitive data.

Mitigation Strategies

Upgrade Consul to version 2.0.3 or Consul Enterprise to versions 1.21.17, 1.22.11, or 2.0.3 to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart