Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4111 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-16326PATCHED
hashi · tooling

consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

Description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

Affected Products

VendorProductVersions
hashitooling0.1.0

References

  • https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612

Related News (1 articles)

Tier C
VulDB27d ago
CVE-2026-16326 | HashiCorp consul-mcp-server up to 0.1.3 state issue
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
0.1.4
CWECWE-488
PublishedJul 29, 2026
Trending Score2
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 29
CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 11
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 10
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 9
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 29, 2026
Discovered by ZDM
Jul 29, 2026
Patch Available
Jul 29, 2026