CVE-2026-5061
Last modified
CVE-2026-5061 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5061?
How severe is CVE-2026-5061?
How do I fix CVE-2026-5061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50604A vulnerability has been identified in the Acer Agent Servic…4.9
- CVE-2026-50605A vulnerability has been identified in the Acer Agent Servic…7.4
- CVE-2026-50606A vulnerability has been identified in the Acer System Monit…1.2
- CVE-2026-50607A vulnerability has been identified in the Acer System Monit…2.7
- CVE-2026-50608A vulnerability has been identified in the Acer System Monit…1.2
- CVE-2026-50609A vulnerability has been identified in the Acer System Monit…7.4
- CVE-2026-50610A vulnerability has been identified in the Acer System Monit…7.4
- CVE-2026-5062The PrettyLinks – Affiliate Links, Link Branding, Link Track…4.9
- CVE-2026-50622Description: Missing Authorization in Apache Atlas. A missin…8.8
- CVE-2026-50623An authentication bypass vulnerability exists in the OAuth2 …4.8
- CVE-2026-50627The JwtAccessTokenValidator class in Apache CXF fails to val…9.1
- CVE-2026-50628A logic error in OAuthRequestFilter rejects legitimate reque…9.8
Are you affected by CVE-2026-5061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
