CVE-2026-7474 Details
Description
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
A path traversal vulnerability allowing code execution on the client host has been identified in HashiCorp Nomad and Nomad Enterprise versions prior to 2.0.1. This issue arises in the Dynamic Host Volumes feature, where authorized users can create volumes on the client host. A user with host-volume-create permission and read access to nodes can exploit this vulnerability by submitting a host-volume create request that traverses out of the plugin directory, executing a non-plugin executable as the same user as the Nomad agent.
Users are advised to upgrade to HashiCorp Nomad version 2.0.1, or for Nomad Enterprise, to versions 2.0.1, 1.11.5, or 1.10.11. Nomad Enterprise customers unable to upgrade can implement a Sentinel policy to disable external plugins, allowing only the built-in 'mkdir' plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-15-nomad-vulnerable-to-path-traversal-in-dynamic-host-volume-which-may-lead-to-code-execution/77417 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HashiCorp Nomad | >= 1.10.0, <= 2.0.0 (semver) |
CPE
Remediation
| |
| HashiCorp Nomad Enterprise | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion