Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4. | |
| Title | Consul vulnerable to an authorization bypass in the catalog node-write path | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-09-10T19:02:58.403Z
Reserved: 2026-09-08T19:58:12.912Z
Link: CVE-2026-87090
Updated: 2026-09-10T19:02:53.867Z
Status : Awaiting Analysis
Published: 2026-09-10T19:17:37.157
Modified: 2026-09-10T19:45:14.210
Link: CVE-2026-87090
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization