Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp tooling |
|
| Vendors & Products |
Hashicorp
Hashicorp tooling |
Wed, 29 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4. | |
| Title | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode | |
| Weaknesses | CWE-488 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-07-29T19:10:11.027Z
Reserved: 2026-07-20T17:50:16.465Z
Link: CVE-2026-16326
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T20:30:03Z
-
CWE-488
Exposure of Data Element to Wrong Session