Home

Description

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

PUBLISHED Reserved 2026-04-29 | Published 2026-05-12 | Updated 2026-05-13 | Assigner HashiCorp




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

Product status

Default status
unaffected

1.10.0 (semver) before 2.0.1
affected

Default status
unaffected

1.10.0 (semver) before 2.0.1
affected

Credits

This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research

References

discuss.hashicorp.com/...ch-may-lead-to-code-execution/77417

cve.org (CVE-2026-7474)

nvd.nist.gov (CVE-2026-7474)

Download JSON