PT-2026-40386 · Hashicorp · Nomad

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-8052

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad exec2 task driver versions prior to 0.1.2
Description The exec2 task driver allows arbitrary file read and write operations on the client host with the privileges of the Nomad process user. This is possible through a symlink attack, where a symbolic link (a file that points to another file or directory) is used to access unauthorized locations on the host system.
Recommendations Update the exec2 task driver to version 0.1.2.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06945
CVE-2026-8052
GHSA-WQWC-X3RC-2XW6

Affected Products

Nomad