Skip to content
HashiCorpCVE-2026-14896

HashiCorp Nomad: improper authorization

Medium4.2CVE-2026-14896 · Published Jul 8, 2026 · updated Jul 9, 2026

HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Nomad
Product
>= 0.4.1, < 2.0.42.0.4
Nomad Enterprise
Product
>= 0.4.1, < 2.0.42.0.4
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Nomad: missing authorization
High7.7Jul 8
HashiCorp Nomad: link following
High8.7Jul 8
HashiCorp Tooling: link following
Medium4.7Jul 8
HashiCorp Shared library: denial of service
Medium4.9Jul 8
HashiCorp Terraform Enterprise: path traversal
High7.7Jul 6
HashiCorp Vault: path traversal
Medium4.4Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.