AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-14891

HIGH · CVSS 8.7 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects HashiCorp Nomad and Nomad Enterprise, specifically within the Docker task driver, allowing job submitters to bypass restrictions on volume bind mounts and access host file systems. This could lead to unauthorized reading and writing of files on the host, posing a significant security risk. Organizations using these versions of Nomad should prioritize applying the updates to mitigate potential exploitation.

CVE
CVE-2026-14891
Severity
HIGH
CVSS
8.7
EPSS
0.32%
Docker

Original NVD Description

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.