AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19016

MEDIUM · CVSS 4.2 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users with network access to the Consul server RPC port to delete arbitrary sessions without the necessary {{session:write}} ACL permission, potentially leading to unauthorized session management. This could compromise the integrity and availability of session data within Consul deployments. Organizations using Consul Community Edition or Consul Enterprise versions 1.19.1 through 2.0.2 should prioritize upgrading to the patched versions to mitigate this risk.

CVE
CVE-2026-19016
Severity
MEDIUM
CVSS
4.2
EPSS
0.21%

Original NVD Description

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.