In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp tooling |
|
| Vendors & Products |
Hashicorp
Hashicorp tooling |
Wed, 29 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4. | |
| Title | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode | |
| Weaknesses | CWE-488 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-07-29T19:10:11.027Z
Reserved: 2026-07-20T17:50:16.465Z
Link: CVE-2026-16326
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T20:30:03Z
Weaknesses