CVE-2020-12797: Hashicorp Consul

Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.

HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

Affected products

  • Hashicorp Consul: from 1.4.0, before 1.6.6 (fixed in 1.6.6); from 1.4.0, up to and including 1.6.6; from 1.7.0, before 1.7.4 (fixed in 1.7.4)

Published 2020-06-11. Last modified 2026-06-17.