CyberRota Analysis
AI-GeneratedThe vulnerability affects HashiCorp Nomad and Nomad Enterprise, specifically within the Docker task driver, allowing job submitters to bypass restrictions on volume bind mounts and access host file systems. This could lead to unauthorized reading and writing of files on the host, posing a significant security risk. Organizations using these versions of Nomad should prioritize applying the updates to mitigate potential exploitation.
Original NVD Description
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.