HashiCorp security advisory (AV26-910)
MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products:
- Consul
- Prior to 2.0.4
- Consul Enterprise
- 1.0 Prior to 1.21.18
- 21.0 Prior to 1.21.18
- 9.0 Prior to 1.21.18
- consul-template
- Prior to 0.43.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path
- HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling
- HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh
- Security - HashiCorp Discuss
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Read at cyber.gc.ca ↗Official Source
Coverage
One outlet has carried this so far.
2026-09-11 13:10 UTC
Related stories
- Windows 11 KB5124008 update breaks domain trust for some users
BleepingComputer · 2026-09-16
- CISA decides weekly vulnerability bulletin isn't necessary anymore
The Register · 2026-09-16
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16