CyberRota Analysis
AI-GeneratedThe vulnerability allows authenticated users with network access to the Consul server RPC port to delete arbitrary sessions without the necessary {{session:write}} ACL permission, potentially leading to unauthorized session management. This could compromise the integrity and availability of session data within Consul deployments. Organizations using Consul Community Edition or Consul Enterprise versions 1.19.1 through 2.0.2 should prioritize upgrading to the patched versions to mitigate this risk.
Original NVD Description
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.