Security Updates for HashiCorp Consul
HashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.
HashiCorp has issued a security advisory (HCSEC-2026-25) addressing multiple undisclosed vulnerabilities affecting Consul Community Edition and Consul Enterprise. The affected versions include Consul Community Edition prior to 2.0.3, and Consul Enterprise versions prior to 2.0.3, 1.22.11, and 1.21.17. While the advisory provides information regarding the remediation paths, it does not detail specific exploitation techniques, CVE identifiers, or observed malicious behavior. Administrators of Consul infrastructure should review the official HashiCorp Discuss security page and apply the recommended software updates to the specified versions to ensure the security and stability of their service mesh and configuration management environments.
Impact
Failure to apply the necessary security updates leaves Consul installations exposed to potentially exploitable vulnerabilities. Organizations utilizing Consul for service discovery, configuration, and segmentation across cloud, Linux, Windows, or macOS environments are encouraged to prioritize patching to avoid potential compromise of sensitive infrastructure control planes.
Recommendation
- Review the official HashiCorp advisory (HCSEC-2026-25) at the provided URL.
- Patch all instances of Consul Community Edition to version 2.0.3 or higher.
- Patch all instances of Consul Enterprise to versions 2.0.3, 1.22.11, or 1.21.17, depending on the current branch.
Mitigations
Upgrade Consul Community Edition and Consul Enterprise to the specified patched versions.
Consul vulnerabilities
Indicators of compromise
1
url
| Type | Value |
|---|---|
| url | https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629 |