CVE-2026-16328
published 2026-07-29CVE-2026-16328: In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the…
PriorityP354high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.23%
14.0th percentile
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashicorp | tooling | >= 0.1.0 < 0.1.4 | 0.1.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a requ
ghsa_unreviewed·2026-07-29·CVSS 8.6
CVE-2026-16328 [HIGH] CWE-918 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a requ
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
VulDB
HashiCorp consul-mcp-server up to 0.1.3 Consul Backend Address server-side request forgery
vuldb·2026-07-29·CVSS 8.6
CVE-2026-16328 [HIGH] HashiCorp consul-mcp-server up to 0.1.3 Consul Backend Address server-side request forgery
A vulnerability was found in HashiCorp consul-mcp-server up to 0.1.3. It has been rated as critical. Affected is an unknown function of the component Consul Backend Address Handler. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-16328. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-29
Published