Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-16326Session token exposure in consul-mcp-server

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

View on NVD

Analysis

Consul-mcp-server no logra aislar correctamente el estado de las sesiones, permitiendo que el token de autenticación de un cliente sea reutilizado por otros de forma involuntaria. Esta vulnerabilidad en el modo stateless permite el acceso no autorizado a recursos protegidos de Consul mediante el secuestro de credenciales entre peticiones.

Relevant roles

BackendCloudCyberSecurityGoKubernetesDocker

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: LOW
Weakness (CWE): CWE-488

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

Published: 7/29/2026, 7:16:44 PM
Last modified: 7/29/2026, 8:17:02 PM

References

HomeEventsBlogResourcesCoursesTeam