Consul L7 Intent Auth Bypass via Custom Public Listener (<=2.0.2)
CVE-2026-15970 Published on August 7, 2026

L7 intention authorization bypass via custom public listener
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

NVD

Weakness Type

Use of Non-Canonical URL Paths for Authorization Decisions

The software defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.


Products Associated with CVE-2026-15970

Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.

 

Affected Versions

HashiCorp Consul: HashiCorp Consul Enterprise: