Description
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Problem types
CWE-59: Improper Link Resolution Before File Access (Link Following)
Product status
0.9.0 (semver) before 2.0.1
0.9.0 (semver) before 2.0.1
Credits
This issue was identified by Alex Manson (Aiven / NeuroWinter).
References
discuss.hashicorp.com/...t-host-through-symlink-attack/77416