Description
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Published: 2026-07-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Nomad Docker task driver contains a logic flaw that does not enforce the allow_privileged restriction for host namespace mode. This omission permits an authenticated user who can submit or modify a Nomad job to launch a container that shares the host’s namespace. The container thereby gains the same visibility and control as the Nomad client process, enabling it to read or modify the underlying Linux host or to other workloads scheduled on the same client. The vulnerability is an instance of Improper Authorization (CWE-862).

Affected Systems

Affected systems include HashiCorp Nomad Community Edition versions prior to 2.0.4 and HashiCorp Nomad Enterprise versions prior to 2.0.4, 1.11.8, and 1.10.14 that are running the Docker driver with host namespace mode enabled on any supported platform

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating high severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is very low, but not zero. It is not listed in the CISA KEV catalog, meaning no widespread exploitation is publicly known. An attacker who is an authenticated Nomad job submitter can create a job payload that requests host‑namespace Docker mode; because the allow_privileged flag is not enforced, the resulting container inherits host privileges, granting it full access to host resources and other workloads on the same client.

Generated by OpenCVE AI on July 28, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Nomad Community Edition 2.0.4 or Nomad Enterprise 1.11.8, 1.10.14, or 2.0.4 where the allow_privileged restriction is enforced for host‑namespace mode.
  • If an upgrade is not feasible, restrict job‑submission privileges to trusted accounts and audit existing job definitions for host‑namespace Docker usage, removing or disabling it where possible.
  • Configure the Nomad Docker driver to disallow host‑namespace mode or to require the allow_privileged flag, ensuring proper authorization is enforced.
  • Deploy runtime security controls to monitor and restrict containers that acquire host‑namespace privileges, alerting on unauthorized host

Generated by OpenCVE AI on July 28, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp nomad
Hashicorp nomad Enterprise
Vendors & Products Hashicorp
Hashicorp nomad
Hashicorp nomad Enterprise

Wed, 08 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Title Nomad Docker driver Linux host namespace bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Hashicorp Nomad Nomad Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-07-08T20:37:39.961Z

Reserved: 2026-07-01T20:10:53.797Z

Link: CVE-2026-14373

cve-icon Vulnrichment

Updated: 2026-07-08T20:37:37.293Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses