Consul Auth Bypass in Connect Mesh via Unescaped Service Names (2.0.3)
CVE-2026-88021 Published on September 10, 2026
Consul vulnerable to an authorization bypass in the Connect service mesh
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Weakness Type
Incorrect Regular Expression
The software specifies a regular expression in a way that causes data to be improperly matched or compared. When the regular expression is used in protection mechanisms such as filtering or validation, this may allow an attacker to bypass the intended restrictions on the incoming data.
Products Associated with CVE-2026-88021
Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.
Affected Versions
HashiCorp Consul:- Version 1.9.0 and below 2.0.4 is affected.
- Version 1.9.0 and below 2.0.4 is affected.