CVE-2026-16326
critical · 10In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
10
CVSS
0.3%
EPSS (exploit prob.)
23rd
EPSS percentile
2026-07-29
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Weaknesses
CWE-488
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-16326