Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp consul Hashicorp consul Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp consul Hashicorp consul Enterprise |
Fri, 07 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. | |
| Title | Authorization bypass for session deletion in the transaction API | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published: 2026-08-07T19:18:08.980Z
Updated: 2026-08-10T18:24:50.823Z
Reserved: 2026-08-05T20:21:36.890Z
Link: CVE-2026-19016
Updated: 2026-08-10T17:51:17.470Z
Status : Awaiting Analysis
Published: 2026-08-07T20:16:50.530
Modified: 2026-08-28T15:47:00.217
Link: CVE-2026-19016