← All CVEs

CVE-2026-16326

critical · 10

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

10
CVSS
0.3%
EPSS (exploit prob.)
23rd
EPSS percentile
2026-07-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Weaknesses

CWE-488

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-16326