VulnSea

consul_enterprise vulnerabilities

CVEs whose affected-version data names the consul_enterprise package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-87090High· 8.3
2w ago

Consul vulnerable to an authorization bypass in the catalog node-write path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…

TwilightHashiCorp · ConsulEPSS 0.21%via CVEORG
CVE-2026-87106Medium· 6.5
2w ago

Consul vulnerable to a denial of service in the native RPC listener

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …

SunlitHashiCorp · ConsulEPSS 0.24%via CVEORG
CVE-2026-88021High· 7.5
2w ago

Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…

TwilightHashiCorp · ConsulEPSS 0.24%via CVEORG
CVE-2026-87107Medium· 5.4
2w ago

Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…

SunlitHashiCorp · ConsulEPSS 0.23%via CVEORG
consul_enterprise vulnerabilities (CVEs) · VulnSea