CVE detail
CVE-2019-12291 — CVE-2019-12291
Published 2019-06-06 · Modified 2026-06-17 · Vendor hashicorp · Product consul · Source nvd
HIGH
severity
CVSS-derived band
0.0116
EPSS probability
exploitation probability, 30d
64.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References