What is CVE-2026-19016?
CVE-2026-19016: In Consul versions 1.19.1 through 2.0.2, the {{session:write}} ACL permission is not enforced for session deletion operations submitted via the transaction API. This allows an authenticated attacker with network access to the Consul server RPC port to delete arbitrary sessions. Upgrading to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-19016: Consul tətbiqinin 1.19.1-dən 2.0.2-ə qədər olan versiyalarında, transaction API üzərindən göndərilən session silmə əməliyyatları üçün {{session:write}} ACL icazəsi düzgün tətbiq edilmir. Bu zəiflik autentifikasiya olunmuş istifadəçiyə şəbəkə üzərindən ixtiyari sessionları silməyə imkan verir. Təhlükəsizlik üçün Consul-un ən son versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which Consul versions are affected by CVE-2026-19016?
Consul versions 1.19.1 through 2.0.2 are affected by this vulnerability.
What does CVE-2026-19016 allow an attacker to do?
It allows an authenticated attacker to delete arbitrary sessions over the network because the {{session:write}} ACL permission is not enforced for session deletion operations submitted via the transaction API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.