CVE-2026-6959 Details
Description
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
A vulnerability allowing arbitrary file read and write on the client host has been identified in HashiCorp Nomad and Nomad Enterprise versions prior to 2.0.1. This issue arises from a symlink attack, where an attacker can manipulate named pipe symlinks for a workload's log files. As a result, the attacker gains access to the host's filesystem with the privileges of the Nomad process user. This vulnerability is particularly concerning because it exploits the filesystem isolation of Nomad task drivers, potentially leading to unauthorized access or modification of files on the client host.
Users are advised to upgrade to Nomad 2.0.1, 1.11.5, 1.10.11, or newer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-14-nomad-arbitrary-file-read-write-on-client-host-through-symlink-attack/77416 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HashiCorp Nomad | >= 0.9, <= 2.0.0 |
CPE
Remediation
| |
| HashiCorp Nomad Enterprise | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion