SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16326

CRITICAL · CVSS 10 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The consul-mcp-server versions 0.1.0 to 0.1.3 are vulnerable due to improper session state isolation in stateless mode, potentially allowing one client's Consul authentication token to be exploited by other clients. This critical vulnerability could lead to unauthorized access and manipulation of resources. Organizations using affected versions should prioritize upgrading to version 0.1.4 to mitigate the risk of token misuse.

CVE
CVE-2026-16326
Severity
CRITICAL
CVSS
10
EPSS
0.30%

Original NVD Description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.