Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-16326: Consul MCP Server Exposes Client Credentials in Stateless Mode

CVE-2026-16326 · published 18 days ago
Summary

A security issue in Consul MCP Server versions 0.1.0 to 0.1.3 allows one client's login credentials to be used by other clients. This means unauthorized access to your Consul data is possible. Update to version 0.1.4 to fix the issue.

What to do
  • Update consul to version 0.1.4.
  • Update hashicorp tooling to version 0.1.4 or later.
Affected software
Ecosystem VendorProductAffected versions
hashicorp tooling < 0.1.4
Bitnami consul >= 0.1.0, < 0.1.4
Fix: upgrade to 0.1.4
Original advisory text
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-488Exposure of Data Element to Wrong Session
Timeline
Published17 Aug 2026
Updated30 Aug 2026
First seen29 Jul 2026
Sources
CVE-2026-16326 · MITRE
Monitor software like this
Free during beta