CVE-2026-16326: CWE-488: Exposure of Data Element to Wrong Session in HashiCorp Tooling
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
AI Analysis
Technical Summary
In consul-mcp-server versions 0.1.0 up to 0.1.3, session state was not properly isolated when operating in stateless mode. This flaw could allow an attacker to use a previously issued Consul authentication token from one client for requests made by other clients, effectively exposing authentication credentials across sessions. The vulnerability is identified as CWE-488 (Exposure of Data Element to Wrong Session). It is resolved in version 0.1.4 of consul-mcp-server.
Potential Impact
Successful exploitation can lead to unauthorized use of Consul authentication tokens by other clients, resulting in potential unauthorized access to protected resources and services. The CVSS v3.1 base score is 10.0 (critical), reflecting network attack vector, no required privileges or user interaction, complete confidentiality and integrity impact, and low availability impact.
Mitigation Recommendations
Upgrade consul-mcp-server to version 0.1.4 or later to apply the official fix that properly isolates session state in stateless mode. No other mitigation or temporary workaround is indicated in the available data.
CVE-2026-16326: CWE-488: Exposure of Data Element to Wrong Session in HashiCorp Tooling
Description
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
CVSS v3.1
Score 10.0critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In consul-mcp-server versions 0.1.0 up to 0.1.3, session state was not properly isolated when operating in stateless mode. This flaw could allow an attacker to use a previously issued Consul authentication token from one client for requests made by other clients, effectively exposing authentication credentials across sessions. The vulnerability is identified as CWE-488 (Exposure of Data Element to Wrong Session). It is resolved in version 0.1.4 of consul-mcp-server.
Potential Impact
Successful exploitation can lead to unauthorized use of Consul authentication tokens by other clients, resulting in potential unauthorized access to protected resources and services. The CVSS v3.1 base score is 10.0 (critical), reflecting network attack vector, no required privileges or user interaction, complete confidentiality and integrity impact, and low availability impact.
Mitigation Recommendations
Upgrade consul-mcp-server to version 0.1.4 or later to apply the official fix that properly isolates session state in stateless mode. No other mitigation or temporary workaround is indicated in the available data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- HashiCorp
- Date Reserved
- 2026-07-20T17:50:16.465Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a4bfc9c2644c7f8e93eba
Added to database: 07/29/2026, 18:52:44 UTC
Last enriched: 07/29/2026, 19:10:01 UTC
Last updated: 07/30/2026, 00:37:09 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.