CVE-2026-87090: Consul vulnerable to an authorization bypass in the catalog node-write path
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerability (CVE-2026-87090) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consulto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.18 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.12 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Consul and Consul Enterprise deployments are exposed if an attacker has an authenticated token with node-write permission for any node name and can obtain the node ID of a different node they do not control.
What could an attacker do after exploiting the authorization bypass?
The attacker may delete another node's catalog registration and take over that node's identity in the catalog.
Which versions contain the fix?
The issue is fixed in Consul 2.0.4 and in Consul Enterprise 1.21.18, 1.22.12, and 2.0.4.