PT-2026-56005 · Hashicorp · Terraform Enterprise

·

CVE-2026-14468

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Terraform Enterprise versions prior to 2.0.4 Terraform Enterprise versions prior to 1.2.4
Description An issue exists in the version control system (VCS) ingestion of registry modules where the intended boundary on packaged module content is not correctly enforced. This allows an authenticated user to include files from outside the intended repository content within a module and subsequently download them, which may expose sensitive files that are readable by the ingestion process.
Recommendations Update to version 2.0.4. Update to version 1.2.4.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14468

Affected Products

Terraform Enterprise