Consul Auth Bypass: Catalog Dereg Path (2.0.3) Deletes PeerImported Objects
CVE-2026-87107 Published on September 10, 2026
Consul vulnerable to an authorization bypass in the catalog deregistration path
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-87107 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-87107
Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.
Affected Versions
HashiCorp Consul:- Version 1.21.0 and below 2.0.4 is affected.
- Version 1.21.0 and below 2.0.4 is affected.