CVE-2026-2808: Hashicorp Consul
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Affected products
- Hashicorp Consul: before 1.22.5 (fixed in 1.22.5)
- Hashicorp Consul Enterprise: before 1.22.5 (fixed in 1.22.5)
Published 2026-03-12. Last modified 2026-06-17.