CyberRota Analysis
AI-GeneratedThe vulnerability affects HashiCorp Nomad and Nomad Enterprise, specifically in the Docker task driver, where the allow_privileged restriction is not enforced for host namespace mode options. This oversight allows authenticated job submitters to potentially execute containers with host-level access, compromising sensitive information from the host or other workloads. Organizations utilizing Nomad for container orchestration should prioritize applying the updates in versions 2.0.4, 1.11.8, or 1.10.14 to mitigate this risk.
Original NVD Description
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.