Home

Description

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

PUBLISHED Reserved 2026-04-24 | Published 2026-05-12 | Updated 2026-05-12 | Assigner HashiCorp




MEDIUM: 6.0CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

Problem types

CWE-59: Improper Link Resolution Before File Access (Link Following)

Product status

Default status
unaffected

0.9.0 (semver) before 2.0.1
affected

Default status
unaffected

0.9.0 (semver) before 2.0.1
affected

Credits

This issue was identified by Alex Manson (Aiven / NeuroWinter).

References

discuss.hashicorp.com/...t-host-through-symlink-attack/77416

cve.org (CVE-2026-6959)

nvd.nist.gov (CVE-2026-6959)

Download JSON