Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19016

Опубликовано: 07 авг. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

A flaw was found in Consul. An authenticated caller with network access to the Consul server RPC port could bypass authorization checks. This vulnerability occurs because the system did not enforce the session:write Access Control List (ACL) permission for session deletion operations submitted through the transaction API. This allows an attacker to delete arbitrary sessions without the necessary permissions, leading to unauthorized session termination.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2512622consul: Consul: Authorization bypass allows arbitrary session deletion via transaction API

EPSS

Процентиль: 12%
0.00213
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
9 дней назад

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

CVSS3: 4.2
nvd
9 дней назад

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

CVSS3: 4.2
debian
9 дней назад

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 di ...

CVSS3: 4.2
github
9 дней назад

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

EPSS

Процентиль: 12%
0.00213
Низкий

4.2 Medium

CVSS3

Уязвимость CVE-2026-19016