PT-2026-56533 · Hashicorp · Nomad+1

·

CVE-2026-14373

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nomad Community Edition versions prior to 2.0.4 Nomad Enterprise versions prior to 2.0.4 Nomad Enterprise versions prior to 1.11.8 Nomad Enterprise versions prior to 1.10.14
Description HashiCorp Nomad and Nomad Enterprise failed to enforce the allow privileged restriction for the Docker task driver's host namespace mode options. This flaw allows an authenticated job submitter to execute a container within a host namespace, potentially granting unauthorized access to information on the host or other workloads residing on the same client.
Recommendations Update Nomad Community Edition to version 2.0.4. Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14373

Affected Products

Nomad
Nomad Enterprise