Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2808

Опубликовано: 11 мар. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privileged attacker can exploit this vulnerability to perform arbitrary file reads. This could lead to the disclosure of sensitive information from the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorNot affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kube-state-metrics-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/prometheus-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2446879github.com/hashicorp/consul: HashiCorp Consul: Arbitrary file read via Kubernetes authentication configuration

EPSS

Процентиль: 39%
0.00475
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
nvd
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
debian
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22. ...

CVSS3: 6.8
github
5 месяцев назад

Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication

CVSS3: 6.8
fstec
5 месяцев назад

Уязвимость инструмента настройки сервисов HashiCorp Consul Community Edition и Consul Enterprise, связанная с некорректным определением ссылки перед доступом к файлу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 39%
0.00475
Низкий

6.8 Medium

CVSS3