PT-2026-56576 · Hashicorp+2 · Nomad+1

CVE-2026-14896

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nomad Community Edition versions prior to 2.0.4 Nomad Enterprise versions prior to 2.0.4 Nomad Enterprise versions prior to 1.11.8 Nomad Enterprise versions prior to 1.10.14
Description A cross-namespace authorization bypass exists in the dynamic host volumes feature. This issue allows an operator with host volume delete permissions in one namespace to delete a sticky volume claim associated with a job in a different namespace.
Recommendations Update Nomad Community Edition to version 2.0.4. Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14896

Affected Products

Nomad
Nomad Enterprise