CVE-2021-41805

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-41805

OS impact

OSVersionStatusFixed in
arch archaffected
debian debianbullseyefixed0

References

Verify integrity in audit chain (admin only). AS-IS.