Hashicorp · Terraform Enterprise · CVE-2026-14468
**Name of the Vulnerable Software and Affected Versions**
Terraform Enterprise versions prior to 2.0.4
Terraform Enterprise versions prior to 1.2.4
**Description**
An issue exists in the version control system (VCS) ingestion of registry modules where the intended boundary on packaged module content is not correctly enforced. This allows an authenticated user to include files from outside the intended repository content within a module and subsequently download them, which may expose sensitive files that are readable by the ingestion process.
**Recommendations**
Update to version 2.0.4.
Update to version 1.2.4.