CVE-2026-6959

Source
https://cve.org/CVERecord?id=CVE-2026-6959
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6959.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6959
Aliases
Downstream
Published
2026-05-12T18:59:09.029Z
Modified
2026-07-15T01:49:10.023841868Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
Nomad vulnerable to arbitrary file read/write on client host through symlink attack
Details

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Database specific
{
    "cwe_ids": [
        "CWE-59"
    ],
    "cna_assigner": "HashiCorp",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6959.json"
}
References

Affected packages

Git / github.com/hashicorp/nomad

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/nomad
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "2.0.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6959.json"