HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5. | |
| Title | Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-03-11T23:08:32.414Z
Reserved: 2026-02-19T15:17:24.550Z
Link: CVE-2026-2808
No data.
Status : Received
Published: 2026-03-12T00:16:11.770
Modified: 2026-03-12T00:16:11.770
Link: CVE-2026-2808
No data.
OpenCVE Enrichment
No data.