Threat · curated 31 Jul 2026

HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server - Security - HashiCorp Discuss

Coverage timeline

29 Jul 2026hashicorp.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

HashiCorp's consul-mcp-server flaws show how an MCP server exposed to AI agents can be coerced into leaking credentials and forging requests, a direct risk to anyone deploying agent-accessible infrastructure tooling.

HashiCorp advisory HCSEC-2026-24 discloses two vulnerabilities in consul-mcp-server (0.1.0-0.1.3, fixed in 0.1.4), an MCP server that gives AI agents access to a Consul cluster. CVE-2026-16328 lets a client override the Consul backend address to redirect API traffic and exfiltrate the configured Consul token (SSRF), and CVE-2026-16326 allows cross-tenant reuse of one client's Consul auth token in stateless mode.