Host Namespace Bypass Vulnerability in HashiCorp Nomad and Nomad Enterprise
CVE-2026-14373

7.7HIGH

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
8 July 2026

What is CVE-2026-14373?

A security limitation in HashiCorp Nomad and Nomad Enterprise relates to the allow_privileged restriction concerning the Docker task driver's host namespace mode options. This flaw could enable an authenticated job submitter to execute a container in a host namespace, potentially compromising sensitive information belonging to the host or other workloads running on the same client. This vulnerability poses a significant risk as it undermines container isolation, allowing unauthorized access to host resources.

Affected Version(s)

Nomad 64 bit 0.4.1 < 2.0.4

Nomad Enterprise 64 bit 0.4.1 < 2.0.4

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Deniz Onur Duzgun (@dduzgun-security).
.