


Perceptive Security
SOC/SIEM Consultancy

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication to…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 20:03:55
Source:
nvd.nist.gov
Identity & Access, Cloud & Virtualization, Network Infrastructure
CVE-2026-16326 affects consul-mcp-server versions 0.1.0 through 0.1.3, where session state was not properly isolated in stateless mode. This flaw may allow one client's Consul authentication token to be leveraged for subsequent requests made by other clients, effectively enabling unauthorized access or privilege escalation. The vulnerability is classified as high severity due to the potential for authentication token leakage across client sessions. HashiCorp has addressed the issue in consul-mcp-server version 0.1.4. The advisory was published by HashiCorp on their security discussion forum alongside other vulnerabilities affecting the same product. Users running affected versions are strongly advised to upgrade immediately to mitigate the risk of token misuse.
Technical details
Mitigation steps:
Affected products:
consul-mcp-server 0.1.0
consul-mcp-server 0.1.1
consul-mcp-server 0.1.2
consul-mcp-server 0.1.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16326
https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
