discuss.hashicorp.com
https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612 CVE-2026-16326
CRITICAL
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Record summary
CVE-2026-16326 has a selected CVSS score of 10.0 (critical).
Description
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ToolingBrowse HashiCorp / ToolingDefault status: unaffected | CVE List | 0.1.0 to < 0.1.4 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-16326