NVD - CVE-2026-7474 (original) (raw)
New CVE Received from HashiCorp Inc. 5/12/2026 4:16:46 PM
| Action | Type | Old Value | New Value |
|---|---|---|---|
| Added | Description | HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11. | |
| Added | CVSS V3.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | |
| Added | CWE | CWE-22 | |
| Added | Reference | https://discuss.hashicorp.com/t/hcsec-2026-15-nomad-vulnerable-to-path-traversal-in-dynamic-host-volume-which-may-lead-to-code-execution/77417 |