Host Namespace Bypass Vulnerability in HashiCorp Nomad and Nomad Enterprise
CVE-2026-14373
7.7HIGH
What is CVE-2026-14373?
A security limitation in HashiCorp Nomad and Nomad Enterprise relates to the allow_privileged restriction concerning the Docker task driver's host namespace mode options. This flaw could enable an authenticated job submitter to execute a container in a host namespace, potentially compromising sensitive information belonging to the host or other workloads running on the same client. This vulnerability poses a significant risk as it undermines container isolation, allowing unauthorized access to host resources.
Affected Version(s)
Nomad 64 bit 0.4.1 < 2.0.4
Nomad Enterprise 64 bit 0.4.1 < 2.0.4
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Deniz Onur Duzgun (@dduzgun-security).