LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-16326

Published
CVSS10
Severitycritical
WeaknessCWE-488
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-16326

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-16326.