A vulnerability was found in HashiCorp consul-mcp-server up to 0.1.3. It has been rated as critical. Affected is an unknown function of the component Consul Backend Address Handler. The manipulation leads to server-side request forgery.

This vulnerability is documented as CVE-2026-16328. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.