CVE-2026-16326
published 2026-07-29CVE-2026-16326: In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication…
PriorityP264critical10CVSS 3.1
AVNACLPRNUINSCCHIHAL
EPSS
0.30%
22.1th percentile
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashicorp | tooling | >= 0.1.0 < 0.1.4 | 0.1.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests f
ghsa_unreviewed·2026-07-29·CVSS 10.0
CVE-2026-16326 [CRITICAL] CWE-488 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests f
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
VulDB
HashiCorp consul-mcp-server up to 0.1.3 state issue
vuldb·2026-07-29·CVSS 10.0
CVE-2026-16326 [CRITICAL] HashiCorp consul-mcp-server up to 0.1.3 state issue
A vulnerability was found in HashiCorp consul-mcp-server up to 0.1.3. It has been declared as critical. This impacts an unknown function. Executing a manipulation can lead to state issue.
This vulnerability is registered as CVE-2026-16326. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-29
Published