Hashicorp Consul API Unauthenticated Access

medium Web App Scanning Plugin ID 115321

Synopsis

Hashicorp Consul API Unauthenticated Access

Description

HashiCorp Consul exposes its HTTP API and Web UI without authentication. When ACLs are not enabled, a remote unauthenticated attacker can read the service catalog, nodes, and key/value store (which may contain secrets), and register or deregister services.

Solution

Authentication should be enforced to prevent unauthorized access to the Hashicorp Consul API interface.

See Also

https://support.hashicorp.com/hc/en-us/articles/22467862184211-Consul-Web-UI-and-API-is-Accessible-Remotely-if-not-Configured-Properly

Plugin Details

Severity: Medium

ID: 115321

Type: Check Based

Published: 7/28/2026

Updated: 7/28/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5.1

Percentile: 0

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*

Reference Information