CVE-2026-87107: Consul vulnerable to an authorization bypass in the catalog deregistration path
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consulto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.18 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.12 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Frequently Asked Questions
Who can exploit this issue?
A caller needs a local ACL token with either service:write or node:write permission. The issue affects attempts to deregister catalog objects imported from a peered cluster.
What could an attacker remove?
An attacker meeting the ACL permission requirement may delete peer-imported services, checks, or nodes without having authority over the peer origin.
Which releases contain fixes?
The issue is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4.