VYPR
High severity8.3NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-87090

CVE-2026-87090

Description

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Hashicorp/Consulinferred2 versions
    <1.21.18, <2.0.4+ 1 more
    • (no CPE)range: <1.21.18, <2.0.4
    • (no CPE)range: Consul < 2.0.4, Consul Enterprise < 1.21.18, Consul Enterprise < 1.22.12, Consul Enterprise < 2.0.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.