CyberRota Analysis
AI-GeneratedHashiCorp Nomad and Nomad Enterprise are susceptible to a cross-namespace authorization bypass in their dynamic host volumes feature, enabling operators with delete permissions in one namespace to inadvertently delete sticky volume claims in another. This vulnerability could lead to unauthorized data loss or disruption of services across different namespaces. Organizations using these versions of Nomad should prioritize applying the fixes in Community Edition 2.0.4 and Enterprise versions 2.0.4, 1.11.8, or 1.10.14 to mitigate potential risks.
Original NVD Description
HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.