PT-2026-56576 · Hashicorp+2 · Nomad+1
CVE-2026-14896
·
Published
2026-07-08
·
Updated
2026-07-08
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nomad Community Edition versions prior to 2.0.4
Nomad Enterprise versions prior to 2.0.4
Nomad Enterprise versions prior to 1.11.8
Nomad Enterprise versions prior to 1.10.14
Description
A cross-namespace authorization bypass exists in the dynamic host volumes feature. This issue allows an operator with host volume delete permissions in one namespace to delete a sticky volume claim associated with a job in a different namespace.
Recommendations
Update Nomad Community Edition to version 2.0.4.
Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nomad
Nomad Enterprise