CVE-2026-15970: L7 intention authorization bypass via custom public listener
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consul Community Editionto a version that resolves this vulnerability.Fixed in 2.0.3 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.17 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.11 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15970?
CVE-2026-15970 has a medium severity rating of 4.2.
How do I fix CVE-2026-15970?
To fix CVE-2026-15970, ensure that custom public listeners are properly configured to enforce path-based deny intentions.
What systems are affected by CVE-2026-15970?
CVE-2026-15970 affects HashiCorp Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2.
What type of vulnerability is CVE-2026-15970?
CVE-2026-15970 is an L7 intention authorization bypass vulnerability.
What can be exploited due to CVE-2026-15970?
An authenticated mesh workload can potentially access HTTP paths that should be blocked by a path-based deny intention due to this vulnerability.