Description
HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.
Published: 2026-07-06
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HashiCorp Terraform Enterprise contains a path‑traversal flaw in its version control system ingestion of registry modules, allowing an authenticated user to reference files outside the intended repository and download them, which can expose sensitive files read by the ingestion process.

Affected Systems

All instances of Terraform Enterprise whose installed versions are earlier than v2.0.4 or v1.2.4 are affected, as those releases contain the vulnerability.

Risk and Exploitability

The vulnerability has a CVSS score of 7.7 and an EPSS score of less than 1 %, and it is not listed in the CISA KEV catalog. Although an attacker must first authenticate, any privileged user can exploit the flaw to read arbitrary files, which represents a moderate to high risk of data exposure.

Generated by OpenCVE AI on July 26, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Terraform Enterprise to v2.0.4 or v1.2.4.
  • Restrict module ingestion privileges to only trusted users to prevent unauthorized modules from referencing external files.
  • Monitor ingestion logs for anomalous file references or unexpected module uploads to detect potential exploitation attempts.

Generated by OpenCVE AI on July 26, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp terraform Enterprise
Vendors & Products Hashicorp
Hashicorp terraform Enterprise

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.
Title Path traversal allows arbitrary file read in Terraform Enterprise container
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Hashicorp Terraform Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-07-07T13:52:51.836Z

Reserved: 2026-07-02T14:02:23.960Z

Link: CVE-2026-14468

cve-icon Vulnrichment

Updated: 2026-07-07T13:52:45.950Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')