HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
🔗 CVE IDs covered (8)
📋 Description
Bulletin ID: HCSEC-2026-25 Affected Products / Versions: CVE-2026-19012: Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. CVE-2026-19014: Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2. CVE-2026-19015: Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2. CVE-2026-19017: Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2. CVE-2026-19016: Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2. CVE-2026-15970: Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2. CVE-2026-15972: Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2. CVE-2026-19113: Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2. All vulnerabilities are fixed in Consul Community Edition 2.0.3 and Consul Enterprise 2.0.3, 1.22.11, and 1.21.17. Publication Date: August 7, 2026 Summary Consul Community Edition and Consul Enterprise are affected by eight vulnerabilities. CVE-2026-19012 is an authenticated denial of service in the Enterprise-to-Community Edition downgrade path. CVE-2026-19014 is an uncontrolled resource consumption issue in the Connect authorization endpoint that defeats the operator’s cache-disable configuration. CVE-2026-19015 is an uncontrolled resource consumption issue in the Connect CA roots endpoint that defeats the operator’s cache-disable configuration. CVE-2026-19017 is a partial arbitrary file read affecting deployments using the Vault Connect CA provider with JWT or AppRole authentication. CVE-2026-19016 is an authorization bypass in the transaction API that allows session deletion without the required ACL permission. CVE-2026-15970 is an L7 intention authorization bypass affecting services configured with a custom public listener. CVE-2026-15972 is an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. CVE-2026-19113 is an unauthenticated denial of service in several agent HTTP API endpoi…
🎯 Affected products3
- Consul
- Consul Enterprise
- Vault