Junglewise Threat Intelligence

CVE-2026-87107: HashiCorp Consul authorization bypass in catalog deregistration

CVE-2026-87107 · Severity: medium · CVSS 5.4 · Published 2026-09-10

Technologies: HashiCorp Consul Enterprise, HashiCorp Consul. Vendors: HashiCorp.

Executive brief

HashiCorp Consul is a service discovery and networking platform used to manage microservices in distributed clusters. An authorization flaw allows users with limited write permissions to delete services and nodes imported from peered clusters they should not have access to, potentially disrupting service discovery and cross-cluster routing without proper access controls.

Technical details

The catalog deregistration endpoint in Consul failed to properly enforce ownership boundaries between locally managed catalog objects and those imported through cluster peering. An attacker holding a local ACL token with service:write or node:write permissions could craft a deregistration request to remove peer-imported services, checks, or nodes outside their authorization scope. This requires an active cluster peering relationship and local write access, but allows deletion of resources the attacker should not control. The vulnerability affects Consul and Consul Enterprise versions 1.21.0 through 2.0.3 and is fixed in Consul 2.0.4 and Enterprise 1.21.18, 1.22.12, and 2.0.4.

Affected products

  • HashiCorp Consul 1.21.0 through 2.0.3
  • HashiCorp Consul Enterprise 1.21.0 through 2.0.3

Timeline

  • 2026-09-10: disclosed: Published in HCSEC-2026-36
  • 2026-09-10: patched: Fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4

References

Related threats