In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-29 19:16
Updated : 2026-07-30 14:08
NVD link : CVE-2026-16326
Mitre link : CVE-2026-16326
CVE.ORG link : CVE-2026-16326
JSON object : View
Products Affected
No product.
CWE
CWE-488
Exposure of Data Element to Wrong Session
