CVE-2026-2808: Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider
HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2808?
CVE-2026-2808 has been assigned a significant severity rating due to its potential for arbitrary file reading through Kubernetes authentication.
How do I fix CVE-2026-2808?
To fix CVE-2026-2808, upgrade HashiCorp Consul or Consul Enterprise to a version later than 1.21.10 or 1.22.4.
Which versions of HashiCorp Consul are affected by CVE-2026-2808?
HashiCorp Consul versions 1.18.20 to 1.21.10 and below 1.22.4 are affected by CVE-2026-2808.
What types of systems are impacted by CVE-2026-2808?
CVE-2026-2808 impacts installations of HashiCorp Consul and Consul Enterprise utilizing Kubernetes authentication.
Is CVE-2026-2808 an easily exploitable vulnerability?
CVE-2026-2808 can be considered easily exploitable as it allows arbitrary file reads if the system is misconfigured.