CVE-2023-3518: Hashicorp Consul

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.

Affected products

Published 2023-08-09. Last modified 2026-06-17.