Consul Auth Bypass in Connect Mesh via Unescaped Service Names (2.0.3)
CVE-2026-88021 Published on September 10, 2026

Consul vulnerable to an authorization bypass in the Connect service mesh
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

NVD

Weakness Type

Incorrect Regular Expression

The software specifies a regular expression in a way that causes data to be improperly matched or compared. When the regular expression is used in protection mechanisms such as filtering or validation, this may allow an attacker to bypass the intended restrictions on the incoming data.


Products Associated with CVE-2026-88021

Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.

 

Affected Versions

HashiCorp Consul: HashiCorp Consul Enterprise: