Back to CVE List

CVE-2026-16326

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
10.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Vulnerability Description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-488
Source
NVD
Vendor
HashiCorp
Product
Tooling

External References

Discussion (0)

Add Comment

No comments yet. Be the first!