PT-2026-73163 · Opentofu · Opentofu

CVE-2026-74796

·

Published

2026-06-23

·

Updated

2026-08-17

CVSS v4.0

7.0

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions OpenTofu versions prior to 1.11.7
Description During initialization, the software fails to validate existing symlinks within the provider cache directory. This allows an attacker to place a malicious symlink in a trusted working directory, causing the tofu init command to write provider package contents to arbitrary filesystem locations outside the working tree.
Recommendations Update to version 1.11.7 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74796
GHSA-WCMJ-X466-56MM
GO-2026-5705

Affected Products

Opentofu