Sceawere

Vulnerability Detail

CVE-2026-15970UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Consul L7 Intention Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
17h ago
Vendor
HashiCorp
Product
Consul
Attack Type
CWE-647: Non-Canonical URL Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-08-07T20:16:49.863Z",
  "pubdate": "2026-08-07T20:16:49.863Z",
  "executiveSummary": "A vulnerability has been identified in Consul Community Edition and Consul Enterprise, designated as CVE-2026-15970, which involves an L7 intention authorization bypass. This security flaw impacts Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2. The vulnerability arises when a service proxy is explicitly configured with a custom public listener, causing the authorization enforcement mechanism to fail under specific routing conditions. Consequently, an authenticated mesh workload is capable of successfully reaching HTTP paths that should otherwise be strictly blocked by a configured path-based deny intention. The risk implication of this vulnerability is the unauthorized access to sensitive application endpoints within the service mesh, potentially exposing internal services or data that rely on Layer 7 access controls for protection. Exploitation of this vulnerability requires the attacker to possess an authenticated mesh workload within the system, allowing them to leverage the misapplied authorization checks of the service proxy's custom public listener. The issue is fully resolved in Consul 2.0.3, Consul Enterprise 1.21.17, Consul Enterprise 1.22.11, and Consul Enterprise 2.0.3 by applying the official software updates provided by the vendor.",
  "technicalDetails": "CVE-2026-15970 is an authorization bypass vulnerability affecting the Layer 7 (L7) intention enforcement logic within Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2. The vulnerable component is the service proxy configuration mechanism, specifically when utilizing a custom public listener setup. In a standard Consul service mesh deployment, L7 intentions are evaluated by the proxy to enforce path-based access control lists (ACLs) and deny rules for incoming HTTP traffic traversing the mesh. However, when a service proxy is instantiated with a custom public listener, the routing and evaluation path for incoming HTTP requests fails to correctly enforce path-based deny intentions. To exploit this vulnerability, an attacker must operate an authenticated mesh workload, meaning authentication requirements are strictly tied to possessing valid mesh credentials to establish initial connectivity. The privilege requirements are low in terms of mesh participation, as any authenticated workload within the service mesh can initiate the request. Network exposure is localized to the service mesh data plane where the service proxy operates with the custom public listener configuration. During the attack flow, the authenticated mesh workload transmits an HTTP request targeted at a specific path that has been explicitly blocked by a path-based deny intention. Due to the flaw in the service proxy's handling of custom public listeners, the proxy incorrectly bypasses the L7 intention evaluation or fails to match the deny rule against the incoming HTTP path. As a result, the payload and request are forwarded to the upstream service, bypassing the intended security controls. The post-exploitation impact includes unauthorized data access, lateral movement within the application layer, and the ability to interact with restricted backend microservices that were intended to be isolated by network or service mesh policies."
}
CVE-2026-15970: Consul L7 Intention Authorization Bypass (MEDIUM Severity, CVSS: 4.2) - Sceawere