CVE-2026-16326
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16326.json, https://nvd.nist.gov/vuln/detail/CVE-2026-16326, https://github.com/hashicorp/consul-mcp-server