AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15970

MEDIUM · CVSS 4.2 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are susceptible to an L7 intention authorization bypass, allowing authenticated mesh workloads to access HTTP paths that should be restricted by path-based deny intentions when a custom public listener is configured. This vulnerability could lead to unauthorized access to sensitive resources, potentially compromising the integrity of service communications. Organizations using affected versions should prioritize upgrading to Consul 2.0.3 or the specified Enterprise versions to mitigate this risk.

CVE
CVE-2026-15970
Severity
MEDIUM
CVSS
4.2
EPSS
0.16%

Original NVD Description

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.