PatchSiren cyber security CVE debrief
CVE-2026-19012 HashiCorp CVE debrief
CVE-2026-19012 is an authenticated denial of service vulnerability affecting Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. An authorized caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
- Vendor
- HashiCorp
- Product
- Consul
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-08-28
Who should care
Administrators and users of Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 should apply patches and monitor server logs for unexpected agent exits. Additionally, security teams and vulnerability management teams should review the vulnerability details to assess the impact on their environments and plan for mitigations if necessary. Operators of Consul deployments should also verify the configurations and permissions of callers with config-entry write permissions to prevent exploitation. This involves reviewing access controls and ensuring that only authorized personnel have the necessary permissions. Furthermore, monitoring and logging should be enhanced to detect any unusual activity that could indicate an attempted exploit. Compensating controls, such as restricting config-entry write permissions and enhancing monitoring, should be considered while patches are being applied. Asset inventory and configuration management processes should be reviewed to ensure that all affected systems are identified and prioritized for remediation. Rollback and change management procedures should also be evaluated to minimize downtime and ensure a smooth patching process. Source tracking and incident response plans should be updated to address potential exploitation of this vulnerability. By taking these steps, organizations can reduce the risk associated with CVE-2026-19012 and protect their Consul deployments from potential denial of service attacks. It is also recommended to review the official CVE Program record and NVD details for further information on the vulnerability and affected versions. This will help in understanding the vulnerability and implementing appropriate mitigations. The CVE description and NVD details provide information on the vulnerability and affected versions, which can be used to prioritize and plan remediation efforts. Security teams should track exceptions and retest remediated assets to ensure that patches have been successfully applied and that the vulnerability has been mitigated. This involves documenting evidence of remediation and closing the item only after verification has been completed. By following these steps, Consul
Technical summary
CVE-2026-19012 is an authenticated denial of service vulnerability in the Enterprise-to-Community Edition downgrade path of Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. An authorized caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This issue arises from improper handling of configuration entries during the downgrade process, which can lead to a denial of service. Affected deployments should review and apply patches from Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Defensive priority
Medium-priority defensive actions are recommended due to the CVSS score of 5.3 and the potential for denial of service.
Recommended defensive actions
- Review and apply patches from Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
- Restrict config-entry write permissions to authorized callers.
- Monitor Consul server logs for unexpected agent exits.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence is based on official CVE Program and NVD records, as well as a source reference from [email protected]. The CVE description and NVD details provide information on the vulnerability and affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19012 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19012
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19012 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19012
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.