Impact
HashiCorp Nomad and Nomad Enterprise allow an operator who has the host volume delete permission in one namespace to delete a sticky volume claim that belongs to a job in another namespace. This cross‑namespace authorization bypass permits removal of persistent storage content that may contain application data or configuration, thereby violating data integrity and potentially exposing sensitive information. The flaw is a classic access control weakness as identified by CWE‑863.
Affected Systems
The vulnerability impacts HashiCorp Nomad Community Edition versions prior to 2.0.4 and Nomad Enterprise versions prior to 2.0.4, 1.11.8, and 1.10.14. Upgrading to any of these fixed releases removes the flaw.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector, based on the description, is an internal attacker who has host volume delete authority in one namespace; with that privilege, the attacker can delete a volume claim in a different namespace without further escalation.
OpenCVE Enrichment