Hashicorp · Nomad Community Edition · CVE-2026-14891
**Name of the Vulnerable Software and Affected Versions**
Nomad Community Edition versions prior to 2.0.4
Nomad Enterprise versions prior to 2.0.4
Nomad Enterprise versions prior to 1.11.8
Nomad Enterprise versions prior to 1.10.14
**Description**
A sandbox escape exists in the Docker task driver. This issue allows a job submitter to bind-mount a host path into a container, bypassing restrictions even when volume bind mounts are disabled. This could enable an attacker to read and write files directly on the host system.
**Recommendations**
Update Nomad Community Edition to version 2.0.4.
Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.