PT-2026-56556 · Hashicorp · Nomad Community Edition+1

·

CVE-2026-14891

·

Published

2026-07-08

·

Updated

2026-07-09

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nomad Community Edition versions prior to 2.0.4 Nomad Enterprise versions prior to 2.0.4 Nomad Enterprise versions prior to 1.11.8 Nomad Enterprise versions prior to 1.10.14
Description A sandbox escape exists in the Docker task driver. This issue allows a job submitter to bind-mount a host path into a container, bypassing restrictions even when volume bind mounts are disabled. This could enable an attacker to read and write files directly on the host system.
Recommendations Update Nomad Community Edition to version 2.0.4. Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14891

Affected Products

Nomad Community Edition
Nomad Enterprise