CVE-2026-87107
Awaiting Analysis Awaiting Analysis - Queue

Authorization Bypass in Consul Catalog Deregistration

Vulnerability report for CVE-2026-87107, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HashiCorp Inc.

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
hashicorp consul 2.0.4
hashicorp consul_enterprise 1.21.18
hashicorp consul_enterprise 1.22.12
hashicorp consul_enterprise 2.0.4
hashicorp consul From 1.21.0 (inc) to 2.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Consul and Consul Enterprise versions 1.21.0 through 2.0.3 are vulnerable to an authorization bypass in the catalog deregistration path. This allows a local ACL token with service:write or node:write permissions to delete peer-imported catalog objects such as services, checks, or nodes without proper authority over the peer origin. The deregistration endpoint does not enforce ownership boundaries between locally registered and peer-imported objects.

Detection Guidance

To detect this vulnerability, check Consul versions for affected releases (1.21.0 to 2.0.3). Verify if cluster peering is active and if local ACL tokens have service:write or node:write permissions. Review logs for unauthorized deregistration attempts of peer-imported objects.

Impact Analysis

An attacker with a local ACL token and write permissions could delete critical services, checks, or nodes imported from a peered cluster. This could disrupt services, cause data loss, or lead to unauthorized modifications in the Consul environment.

Compliance Impact

This vulnerability could lead to unauthorized deletion or modification of data, potentially violating integrity and availability requirements in GDPR and HIPAA. Unauthorized changes may result in non-compliance with data protection and security standards.

Mitigation Strategies

Upgrade Consul to fixed versions (2.0.4 or Consul Enterprise 1.21.18, 1.22.12, 2.0.4). If peering is not required, disable it. Restrict ACL token permissions to least privilege, removing unnecessary service:write or node:write access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87107. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart