Skip to content
CVSS 8.8 · HIGH

CVE-2026-7474

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

View on NVD

Analysis

HashiCorp Nomad is vulnerable to a path traversal attack that allows arbitrary code execution on the underlying client host. This vulnerability allows an attacker to escape the task sandbox and compromise the physical or virtual server running the workloads. All users of Nomad and Nomad Enterprise should upgrade to versions 2.0.1, 1.11.5, or 1.10.11.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-22

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 8.9%
EPSS: 2026-05-13

Technical description

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Published: 5/12/2026, 8:16:46 PM
Last modified: 5/13/2026, 3:53:17 PM

References

HomeEventsBlogResourcesTeam