{"id":"CVE-2026-87107","title":"Consul vulnerable to an authorization bypass in the catalog deregistration path","summary":"Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cvssSource":"cna","cwe":["CWE-863"],"vendor":"HashiCorp","product":"Consul","affected":["Consul >= 1.21.0 < 2.0.4","consul_enterprise >= 1.21.0 < 2.0.4"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T19:21:57.382969Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T19:22:09.223Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-87107","references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-36-consul-vulnerable-to-an-authorization-bypass-in-the-catalog-deregistration-path/77738"}],"tags":["cve.org"],"epss":0.00229,"epssPercentile":0.13932,"ingestedAt":"2026-09-11T16:45:48.024Z","slug":"CVE-2026-87107","body":"## Overview\n\nConsul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.\n\n## Affected\n\n- `Consul >= 1.21.0 < 2.0.4`\n- `consul_enterprise >= 1.21.0 < 2.0.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}