AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-14373

HIGH · CVSS 7.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects HashiCorp Nomad and Nomad Enterprise, specifically in the Docker task driver, where the allow_privileged restriction is not enforced for host namespace mode options. This oversight allows authenticated job submitters to potentially execute containers with host-level access, compromising sensitive information from the host or other workloads. Organizations utilizing Nomad for container orchestration should prioritize applying the updates in versions 2.0.4, 1.11.8, or 1.10.14 to mitigate this risk.

CVE
CVE-2026-14373
Severity
HIGH
CVSS
7.7
EPSS
0.25%
Docker

Original NVD Description

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.