CVE-2026-87090
Awaiting Analysis Awaiting Analysis - Queue

Authorization Bypass in Consul Catalog Node-Write Path

Vulnerability report for CVE-2026-87090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HashiCorp Inc.

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
hashicorp consul 2.0.4
hashicorp consul_enterprise 1.21.18
hashicorp consul_enterprise 1.22.12
hashicorp consul_enterprise 2.0.4
hashicorp consul to 2.0.4 (exc)
hashicorp consul_enterprise From 1.21.0 (inc) to 1.21.18 (exc)
hashicorp consul_enterprise From 1.22.0 (inc) to 1.22.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87090 is an authorization bypass vulnerability in Consul and Consul Enterprise. It allows an authenticated attacker with a token granting node-write permission on any single node name to delete another node's catalog registration and take over its node identity if they know the target node's ID. This can disrupt services and health checks.

Detection Guidance

To detect this vulnerability, check Consul versions for affected releases (up to 2.0.3). Use commands like 'consul version' or 'consul debug -version' to verify installed versions. Monitor logs for unauthorized node registration deletions or identity takeovers in the catalog.

Impact Analysis

An attacker could disrupt services, manipulate health checks, or take over a node's identity, potentially leading to unauthorized access or service disruptions. Exploiting this requires a valid ACL token with limited node-write access and knowledge of the target node's ID.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access or modification of node identities in Consul deployments. If exploited, it may lead to unauthorized changes in service registrations or health checks, which could compromise data integrity or availability. Organizations handling sensitive data under these regulations should assess their Consul deployments for exposure and apply the provided patches to mitigate risks.

Mitigation Strategies

Upgrade to Consul 2.0.4 or Consul Enterprise versions 1.21.18, 1.22.12, or 2.0.4 to patch the vulnerability. Ensure ACL tokens are properly restricted and avoid granting node-write permissions unless absolutely necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart