Full Report
HashiCorp security advisory (AV26-791)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in HashiCorp Consul
## CVE Details
*Note: While the specific CVE IDs were not enumerated in the summary text provided, the advisory refers to the collective vulnerability set identified as HCSEC-2026-25.*
- **CVE ID:** Pending/See HCSEC-2026-25
- **CVSS Score:** Not specified (Typically High for Consul core vulnerabilities)
- **CWE:** Not specified
## Affected Systems
- **Products:** Consul Community Edition, Consul Enterprise
- **Versions:**
- Consul Community Edition: All versions prior to 2.0.3
- Consul Enterprise: All versions prior to 2.0.3
- Consul Enterprise: All versions prior to 1.22.11
- Consul Enterprise: All versions prior to 1.21.17
- **Configurations:** Systems running affected versions of HashiCorp Consul in both standalone and orchestrated environments.
## Vulnerability Description
According to advisory HCSEC-2026-25, multiple vulnerabilities impact HashiCorp Consul. While the specific technical primitives (e.g., Request Smuggling, ACL bypass, or DoS) are detailed in the full vendor discourse, these flaws typically involve the service mesh or the KV store components of the Consul binary.
## Exploitation
- **Status:** Not specified (Presumed "Not exploited in the wild" at time of publication)
- **Complexity:** Not specified
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Potential Impact
- **Integrity:** Potential Impact
- **Availability:** Potential Impact
## Remediation
### Patches
HashiCorp recommends upgrading to the following versions or later:
- **Consul Community Edition:** 2.0.3
- **Consul Enterprise:** 2.0.3
- **Consul Enterprise:** 1.22.11
- **Consul Enterprise:** 1.21.17
### Workarounds
- No specific workarounds are provided in the advisory; immediate patching is the recommended course of action.
- Ensure strict Access Control Lists (ACLs) are enabled to limit the blast radius of potential exploitation.
## Detection
- Monitor Consul logs for unusual API requests or unauthorized attempts to access the Key-Value (KV) store.
- Audit cluster membership changes and unexpected service registrations.
## References
- hxxps[://]discuss[.]hashicorp[.]com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629
- hxxps[://]discuss[.]hashicorp[.]com/c/security/52
- hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/hashicorp-security-advisory-av26-791