Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.

Subscriptions

Vendors Products
Hashicorp Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18112 Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Github GHSA Github GHSA GHSA-rx97-6c62-55mf Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 22 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00013}

epss

{'score': 0.00015}


Wed, 11 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
Title Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2025-06-11T13:53:55.809Z

Reserved: 2025-05-18T01:47:06.331Z

Link: CVE-2025-4922

cve-icon Vulnrichment

Updated: 2025-06-11T13:52:08.105Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-11T14:15:37.140

Modified: 2025-12-22T16:37:53.027

Link: CVE-2025-4922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-24T09:44:13Z

Weaknesses