SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14361

MEDIUM · CVSS 4.7 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The consul-template library prior to version 0.42.1 is susceptible to a path redirection vulnerability in the writeToFile template helper, which could enable unauthorized file writes outside the designated directory or overwrite existing files. This flaw poses a medium risk, particularly for organizations using this library in their applications, as it could lead to data integrity issues or unauthorized access to sensitive information. Users of affected versions should prioritize upgrading to version 0.42.1 to mitigate potential risks.

CVE
CVE-2026-14361
Severity
MEDIUM
CVSS
4.7
EPSS
0.10%

Original NVD Description

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.