Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-2808

Опубликовано: 12 мар. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

EPSS

Процентиль: 6%
0.00022
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.8
ubuntu
16 дней назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
redhat
16 дней назад

A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privileged attacker can exploit this vulnerability to perform arbitrary file reads. This could lead to the disclosure of sensitive information from the system.

CVSS3: 6.8
debian
16 дней назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22. ...

CVSS3: 6.8
github
16 дней назад

Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication

EPSS

Процентиль: 6%
0.00022
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59