CVE-2026-16326 PUBLISHED

consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

Assigner: HashiCorp
Reserved: 20.07.2026 Published: 29.07.2026 Updated: 29.07.2026

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CVSS Score: 10

Product Status

Vendor HashiCorp
Product Tooling
Versions Default: unaffected
  • affected from 0.1.0 to 0.1.4 (excl.)

Credits

  • This issue was reported by an internal HashiCorp team.

References

Problem Types

  • CWE-488: Exposure of Data Element to Wrong Session CWE

Impacts

  • CAPEC-60: Reusing Session IDs (Session Replay)