top of page
perceptive_background_267k.jpg

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication to…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 20:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Cloud & Virtualization, Network Infrastructure

CVE-2026-16326 affects consul-mcp-server versions 0.1.0 through 0.1.3, where session state was not properly isolated in stateless mode. This flaw may allow one client's Consul authentication token to be leveraged for subsequent requests made by other clients, effectively enabling unauthorized access or privilege escalation. The vulnerability is classified as high severity due to the potential for authentication token leakage across client sessions. HashiCorp has addressed the issue in consul-mcp-server version 0.1.4. The advisory was published by HashiCorp on their security discussion forum alongside other vulnerabilities affecting the same product. Users running affected versions are strongly advised to upgrade immediately to mitigate the risk of token misuse.

Technical details

Mitigation steps:

Affected products:

consul-mcp-server 0.1.0
consul-mcp-server 0.1.1
consul-mcp-server 0.1.2
consul-mcp-server 0.1.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page