Consul L7 Intent Auth Bypass via Custom Public Listener (<=2.0.2)
CVE-2026-15970 Published on August 7, 2026
L7 intention authorization bypass via custom public listener
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Weakness Type
Use of Non-Canonical URL Paths for Authorization Decisions
The software defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.
Products Associated with CVE-2026-15970
Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.
Affected Versions
HashiCorp Consul:- Version 1.20.1 and below 2.0.3 is affected.
- Version 1.20.1 and below 2.0.3 is affected.