Symlink Following Vulnerability in OpenTofu by OpenTofu
CVE-2026-74796

7HIGH

Key Information:

Vendor

Opentofu

Status
Vendor
CVE Published:
16 August 2026

What is CVE-2026-74796?

OpenTofu prior to version 1.11.7 demonstrates a serious flaw in its handling of symbolic links during the provider cache directory initialization. Attackers can exploit this vulnerability by placing a malicious symlink in a supposedly trusted working directory. This can lead to the execution of the 'tofu init' command, which writes provider package contents to arbitrary locations within the file system, potentially exposing sensitive data or compromising system integrity.

Affected Version(s)

opentofu 0 < 1.11.7

opentofu 1.11.7

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.