Home

Description

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

PUBLISHED Reserved 2026-02-19 | Published 2026-03-11 | Updated 2026-04-17 | Assigner HashiCorp




MEDIUM: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-59: Improper Link Resolution Before File Access (Link Following)

Product status

Default status
unaffected

Any version before 1.22.5
affected

Default status
unaffected

Any version before 1.22.5
affected

Credits

This issue was identified by Defang Bo.

References

discuss.hashicorp.com/...netes-authentication-provider/77232

cve.org (CVE-2026-2808)

nvd.nist.gov (CVE-2026-2808)

Download JSON