← Vulnerability feed

Vulnerability record · CVE-2021-41805 · published 12 December 2021

CVE-2021-41805: Hashicorp consul incorrect authorization vulnerability

Hashicorp · Consul

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

8.8 CVSS 3.1 High EPSS 35% · top 1.6% CWE-863 · Incorrect authorization
8.8CVSS 3.1 base score, v2 6.5
35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41805 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-37219Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…EPSS 1.1%8.6CVE-2021-3121Golang protobuf vulnerabilityAn issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" i…EPSS 3.5%8.1CVE-2023-5332Gitlab vulnerabilityPatch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without th…EPSS 0.74%8.1CVE-2019-8336Hashicorp consul vulnerabilityHashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one o…EPSS 1.3%7.5CVE-2023-1297Hashicorp consul vulnerabilityConsul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local servic…EPSS 0.77%7.5CVE-2022-3920Hashicorp consul missing authorization vulnerabilityHashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us…EPSS 0.70%7.5CVE-2022-29153Hashicorp consul server-side request forgery (ssrf) vulnerabilityHashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…EPSS 8.7%7.5CVE-2021-32574Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2021-41805), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.