What is CVE-2026-15970?
CVE-2026-15970 is an L7 intention authorization bypass in Consul Community Edition and Enterprise versions 1.20.1 through 2.0.2, affecting service proxies configured with a custom public listener. An authenticated mesh workload may access HTTP paths blocked by path-based deny intentions. Users should upgrade to a patched version.
Azərbaycanca: CVE-2026-15970, Consul-un Community Edition və Enterprise versiyalarında (1.20.1 - 2.0.2) xüsusi public listener ilə konfiqurasiya olunmuş service proxy-də L7 intention authorization bypass zəifliyidir. Bu, autentifikasiya olunmuş mesh iş yükünə yol əsaslı 'deny' qaydaları ilə bloklanmış HTTP yollarına giriş imkanı verə bilər. İstifadəçilərə verilən versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Consul are affected by CVE-2026-15970?
CVE-2026-15970 affects Consul Community Edition and Enterprise versions 1.20.1 through 2.0.2.
What can an authenticated mesh workload do as a result of CVE-2026-15970?
An authenticated mesh workload may access HTTP paths blocked by path-based deny intentions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.