Executive brief
HashiCorp Consul is a service discovery and networking platform used to manage microservices in distributed clusters. An authorization flaw allows users with limited write permissions to delete services and nodes imported from peered clusters they should not have access to, potentially disrupting service discovery and cross-cluster routing without proper access controls.
Technical details
The catalog deregistration endpoint in Consul failed to properly enforce ownership boundaries between locally managed catalog objects and those imported through cluster peering. An attacker holding a local ACL token with service:write or node:write permissions could craft a deregistration request to remove peer-imported services, checks, or nodes outside their authorization scope. This requires an active cluster peering relationship and local write access, but allows deletion of resources the attacker should not control. The vulnerability affects Consul and Consul Enterprise versions 1.21.0 through 2.0.3 and is fixed in Consul 2.0.4 and Enterprise 1.21.18, 1.22.12, and 2.0.4.
Affected products
- HashiCorp Consul 1.21.0 through 2.0.3
- HashiCorp Consul Enterprise 1.21.0 through 2.0.3
Timeline
- 2026-09-10: disclosed: Published in HCSEC-2026-36
- 2026-09-10: patched: Fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4