CVE-2026-88021
Awaiting Analysis Awaiting Analysis - Queue

Authorization Bypass in Consul Connect Service Mesh

Vulnerability report for CVE-2026-88021, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HashiCorp Inc.

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
hashicorp consul 2.0.4
hashicorp consul_enterprise 1.21.18
hashicorp consul_enterprise 1.22.12
hashicorp consul_enterprise 2.0.4
hashicorp consul From 1.9.0 (inc) to 2.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-185 The product specifies a regular expression in a way that causes data to be improperly matched or compared.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the Consul Connect service mesh. It occurs when Consul fails to properly escape certain characters in service names, namespaces, or partitions. This causes Envoy RBAC rules to be generated too broadly, allowing unauthorized access to services that should be restricted.

Detection Guidance

To detect this vulnerability, check if your Consul or Consul Enterprise version is between 1.9.0 and 2.0.3. Verify if the Connect service mesh is enabled with active intentions. Inspect service names, namespaces, and partitions for special characters that may cause improper escaping in Envoy RBAC rules.

Impact Analysis

If exploited, this vulnerability could allow a service to access destinations it is not authorized to reach. This could lead to unauthorized data access, service disruption, or lateral movement within a network. The impact depends on the affected service mesh configuration and enabled intentions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements such as GDPR or HIPAA. Unauthorized data exposure or access could result in regulatory penalties or breaches of data protection obligations.

Mitigation Strategies

Upgrade to a patched version immediately: Consul 2.0.4 or Consul Enterprise 1.21.18, 1.22.12, or 2.0.4. If upgrading is not possible, disable the Connect service mesh or review and remove any intentions using special characters in service names, namespaces, or partitions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88021. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart