Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication in github.com/hashicorp/consul
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication in github.com/hashicorp/consul
02 / AFFECTED SOFTWARE
Affected packages
96 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication in github.com/hashicorp/consul
05 / REFERENCES
Further evidence
- https://discuss.hashicorp.com/t/hcsec-2026-02-consul-vulnerable-to-arbitrary-file-reads-through-the-vault-kubernetes-authentication-provider/77232
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2808.json
- https://github.com/hashicorp/consul
- https://nvd.nist.gov/vuln/detail/CVE-2026-2808
- https://pkg.go.dev/vuln/GO-2026-4690
- https://github.com/advisories/GHSA-cpfq-66p2-336j