CVE-2026-7474
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
View on NVDAnalysis
HashiCorp Nomad is vulnerable to a path traversal attack that allows arbitrary code execution on the underlying client host. This vulnerability allows an attacker to escape the task sandbox and compromise the physical or virtual server running the workloads. All users of Nomad and Nomad Enterprise should upgrade to versions 2.0.1, 1.11.5, or 1.10.11.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-22EPSS
Technical description
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.