CVE-2026-14468 Details
Description
HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.
An arbitrary file read vulnerability has been identified in HashiCorp Terraform Enterprise versions 1.0.0 through 2.0.3, as well as v202506-1 and v202507-1. The issue arises from the application's version control system (VCS) ingestion of registry modules, which failed to properly enforce boundaries on the content being packaged. This flaw may allow an authenticated user to include files from outside the designated repository into a module, and subsequently download them. Such exploitation could lead to the exposure of sensitive files that are accessible during the ingestion process, including application configurations and secrets.
Users are advised to upgrade to Terraform Enterprise versions 2.0.4 or 1.2.4. As an additional precaution, consider removing module publishing permissions from untrusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 6, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-17-terraform-enterprise-vulnerable-to-arbitrary-file-read/77549 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HashiCorp Terraform Enterprise | v202506-1 v202507-1 ~1.0.0 (semver) ~2.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |
Volerion