CVE-2026-16326
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
10.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Vulnerability Description
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-488
Source
NVD
Vendor
HashiCorp
Product
Tooling
Discussion (0)
Add Comment
No comments yet. Be the first!