CVE-2026-87993
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in Consul-Template via Error Messages

Vulnerability report for CVE-2026-87993, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HashiCorp Inc.

Description

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hashicorp consul-template 0.43.0
hashicorp consul-template From 0.27.2 (inc) to 0.42.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The consul-template library has an information disclosure flaw in its error handling. When errors occur, Vault secret values may appear in error messages, logs, or systems like Nomad task events. This happens because the secret redaction fails to cover all Vault secret formats. Only deployments using Vault KV v1 secrets are unaffected. The issue is fixed in consul-template 0.43.0.

Detection Guidance

Check consul-template logs and error messages for any Vault secret values that appear verbatim. Look for template errors or Nomad task events that may expose secrets. Ensure secret redaction is working correctly by reviewing error handling paths in versions 0.27.2 through 0.42.1.

Impact Analysis

This vulnerability could expose sensitive Vault secret values in error logs or messages, potentially leaking confidential information to unauthorized users. If your system relies on consul-template versions 0.27.2 to 0.42.1, attackers might access secret data through error outputs or logs.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized exposure of sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguarding protected health information. Unauthorized secret leakage violates these standards.

Mitigation Strategies

Upgrade consul-template to version 0.43.0 or later immediately. Review and monitor logs for any exposed secrets. If using Vault KV v1 secrets only, confirm no other secret types are in use that could be affected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87993. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart