CVE-2026-6959

Source
https://cve.org/CVERecord?id=CVE-2026-6959
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6959.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6959
Aliases
Downstream
Related
Published
2026-05-12T18:59:09Z
Modified
2026-08-12T03:51:19Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
Nomad vulnerable to arbitrary file read/write on client host through symlink attack
Details

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6959.json"
}
References

Affected packages

Git / github.com/hashicorp/nomad

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/nomad
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "2.0.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6959.json"