{"api_version":"1","generated_at":"2026-08-14T11:20:35+00:00","cve":"CVE-2026-19016","urls":{"html":"https://cve.report/CVE-2026-19016","api":"https://cve.report/api/cve/CVE-2026-19016.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19016","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19016"},"summary":{"title":"Authorization bypass for session deletion in the transaction API","description":"Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.","state":"PUBLISHED","assigner":"HashiCorp","published_at":"2026-08-07 20:16:50","updated_at":"2026-08-10 19:17:29"},"problem_types":["CWE-22","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)"],"metrics":[{"version":"3.1","source":"security@hashicorp.com","type":"Secondary","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","data":{"baseScore":4.2,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629","name":"https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629","refsource":"security@hashicorp.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19016","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19016","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"HashiCorp","product":"Consul","version":"affected 1.19.1 2.0.3 semver","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"]},{"source":"CNA","vendor":"HashiCorp","product":"Consul Enterprise","version":"affected 1.19.1 2.0.3 semver","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"This issue was reported by Andres Cruciani.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"19016","cve":"CVE-2026-19016","epss":"0.002130000","percentile":"0.117030000","score_date":"2026-08-11","updated_at":"2026-08-12 00:06:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-19016","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-10T17:46:04.198541Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-10T18:24:50.823Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"],"product":"Consul","repo":"https://github.com/hashicorp/consul","vendor":"HashiCorp","versions":[{"lessThan":"2.0.3","status":"affected","version":"1.19.1","versionType":"semver"}]},{"defaultStatus":"unaffected","platforms":["64 bit","32 bit","x86","ARM","MacOS","Windows","Linux"],"product":"Consul Enterprise","repo":"https://github.com/hashicorp/consul","vendor":"HashiCorp","versions":[{"changes":[{"at":"1.21.17","status":"unaffected"},{"at":"1.22.11","status":"unaffected"}],"lessThan":"2.0.3","status":"affected","version":"1.19.1","versionType":"semver"}]}],"credits":[{"lang":"en","value":"This issue was reported by Andres Cruciani."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.</p><br/>"}],"value":"Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3."}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126: Path Traversal"}]}],"metrics":[{"cvssV3_1":{"baseScore":4.2,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-07T19:18:08.980Z","orgId":"67fedba0-ff2e-4543-ba5b-aa93e87718cc","shortName":"HashiCorp"},"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629"}],"source":{"advisory":"HCSEC-2026-25","discovery":"EXTERNAL"},"title":"Authorization bypass for session deletion in the transaction API"}},"cveMetadata":{"assignerOrgId":"67fedba0-ff2e-4543-ba5b-aa93e87718cc","assignerShortName":"HashiCorp","cveId":"CVE-2026-19016","datePublished":"2026-08-07T19:18:08.980Z","dateReserved":"2026-08-05T20:21:36.890Z","dateUpdated":"2026-08-10T18:24:50.823Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-07 20:16:50","lastModifiedDate":"2026-08-10 19:17:29","problem_types":["CWE-22","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)"],"metrics":{"cvssMetricV31":[{"source":"security@hashicorp.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-10T17:46:04.198541Z","id":"CVE-2026-19016","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19016","Ordinal":"1","Title":"Authorization bypass for session deletion in the transaction API","CVE":"CVE-2026-19016","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19016","Ordinal":"1","NoteData":"Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.","Type":"Description","Title":"Authorization bypass for session deletion in the transaction API"}]}}}