What is CVE-2026-19017?
CVE-2026-19017 is a partial arbitrary file read vulnerability in Consul Community Edition and Enterprise versions 1.18.21 through 2.0.2 when using the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may trick Consul into reading sensitive files. Systems using these versions should be patched immediately.
Azərbaycanca: CVE-2026-19017, JWT və ya AppRole autentifikasiyası ilə Vault Connect CA Provider istifadə edərkən Consul Community Edition və Enterprise 1.18.21-dən 2.0.2-ə qədər versiyalarda qismən ixtiyari fayl oxuma zəifliyidir. `operator:write` icazəsi olan imtiyazlı təcavüzkar Consul-u aldadaraq həssas faylları oxutdura bilər. Bu versiyaları istifadə edən sistemlər dərhal yamalanmalıdır.
FAQ2
Under what Consul configuration can CVE-2026-19017 be exploited?
This vulnerability can be exploited only when using the Vault Connect CA provider with JWT or AppRole authentication.
What permission must an attacker have to exploit CVE-2026-19017?
The attacker must be a privileged user with `operator:write` permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.