PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19012 HashiCorp CVE debrief

CVE-2026-19012 is an authenticated denial of service vulnerability affecting Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. An authorized caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Vendor
HashiCorp
Product
Consul
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-28
Advisory published
2026-08-07
Advisory updated
2026-08-28

Who should care

Administrators and users of Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 should apply patches and monitor server logs for unexpected agent exits. Additionally, security teams and vulnerability management teams should review the vulnerability details to assess the impact on their environments and plan for mitigations if necessary. Operators of Consul deployments should also verify the configurations and permissions of callers with config-entry write permissions to prevent exploitation. This involves reviewing access controls and ensuring that only authorized personnel have the necessary permissions. Furthermore, monitoring and logging should be enhanced to detect any unusual activity that could indicate an attempted exploit. Compensating controls, such as restricting config-entry write permissions and enhancing monitoring, should be considered while patches are being applied. Asset inventory and configuration management processes should be reviewed to ensure that all affected systems are identified and prioritized for remediation. Rollback and change management procedures should also be evaluated to minimize downtime and ensure a smooth patching process. Source tracking and incident response plans should be updated to address potential exploitation of this vulnerability. By taking these steps, organizations can reduce the risk associated with CVE-2026-19012 and protect their Consul deployments from potential denial of service attacks. It is also recommended to review the official CVE Program record and NVD details for further information on the vulnerability and affected versions. This will help in understanding the vulnerability and implementing appropriate mitigations. The CVE description and NVD details provide information on the vulnerability and affected versions, which can be used to prioritize and plan remediation efforts. Security teams should track exceptions and retest remediated assets to ensure that patches have been successfully applied and that the vulnerability has been mitigated. This involves documenting evidence of remediation and closing the item only after verification has been completed. By following these steps, Consul

Technical summary

CVE-2026-19012 is an authenticated denial of service vulnerability in the Enterprise-to-Community Edition downgrade path of Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. An authorized caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This issue arises from improper handling of configuration entries during the downgrade process, which can lead to a denial of service. Affected deployments should review and apply patches from Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Defensive priority

Medium-priority defensive actions are recommended due to the CVSS score of 5.3 and the potential for denial of service.

Recommended defensive actions

  • Review and apply patches from Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
  • Restrict config-entry write permissions to authorized callers.
  • Monitor Consul server logs for unexpected agent exits.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence is based on official CVE Program and NVD records, as well as a source reference from [email protected]. The CVE description and NVD details provide information on the vulnerability and affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19012 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19012

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19012 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19012

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.