CVE-2026-2808

medium Red Hat
CVSS v3 Base Score
6.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Published: March 11, 2026
Last Modified: March 11, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privileged attacker can exploit this vulnerability to perform arbitrary file reads. This could lead to the disclosure of sensitive information from the system.

CWE

CWE-59

Affected Products

Logging Subsystem for Red Hat OpenShiftMulticluster Global HubOpenShift ServerlessOpenShift Service Mesh 2Red Hat Advanced Cluster Management for Kubernetes 2Red Hat Ansible Automation Platform 2Red Hat Edge Manager 1Red Hat Enterprise Linux 10Red Hat Enterprise Linux 9Red Hat OpenShift Container Platform 4

References