Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-16326

CRITICAL NVD
CVSS Score 10
Severity CRITICAL
Published Jul 29, 2026
Vendor unknown

Description

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

References