CVE-2026-16326
A flaw in consul‑mcp‑server versions 0.1.0 through 0.1.3 lets a client’s authentication token be reused by other clients, because session state isn’t isolated in stateless mode. The issue is fixed in version 0.1.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
consul‑mcp‑server users running versions 0.1.0 to 0.1.3, typically administrators managing Consul clusters.
Real-world impact
An attacker could hijack another user’s session token and perform actions on the Consul cluster with that user’s privileges, potentially gaining full control of the cluster.
Why this severity
The CVSS score of 10 reflects that the vulnerability requires no authentication or user interaction, and it can compromise confidentiality and integrity of the entire system while having a low impact on availability.
What to do about it
- 01Upgrade consul‑mcp‑server to version 0.1.4 or later.
- 02Restart the consul‑mcp‑server service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 29, 2026 · 17h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 15h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.