Skip to content
HashiCorpCVE-2026-14373

HashiCorp Nomad: missing authorization

High7.7CVE-2026-14373 · Published Jul 8, 2026 · updated Jul 9, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Nomad
Product
>= 0.4.1, < 2.0.42.0.4
Nomad Enterprise
Product
>= 0.4.1, < 2.0.42.0.4
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Nomad: improper authorization
Medium4.2Jul 8
HashiCorp Nomad: link following
High8.7Jul 8
HashiCorp Tooling: link following
Medium4.7Jul 8
HashiCorp Shared library: denial of service
Medium4.9Jul 8
HashiCorp Terraform Enterprise: path traversal
High7.7Jul 6
HashiCorp Vault: path traversal
Medium4.4Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.