Description
HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Published: 2026-07-08
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HashiCorp Nomad and Nomad Enterprise allow an operator who has the host volume delete permission in one namespace to delete a sticky volume claim that belongs to a job in another namespace. This cross‑namespace authorization bypass permits removal of persistent storage content that may contain application data or configuration, thereby violating data integrity and potentially exposing sensitive information. The flaw is a classic access control weakness as identified by CWE‑863.

Affected Systems

The vulnerability impacts HashiCorp Nomad Community Edition versions prior to 2.0.4 and Nomad Enterprise versions prior to 2.0.4, 1.11.8, and 1.10.14. Upgrading to any of these fixed releases removes the flaw.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector, based on the description, is an internal attacker who has host volume delete authority in one namespace; with that privilege, the attacker can delete a volume claim in a different namespace without further escalation.

Generated by OpenCVE AI on July 26, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Nomad Community Edition 2.0.4 or newer, or Nomad Enterprise 2.0.4, 1.11.8, or 1.10.14 or later, to apply the vendor fix.
  • If an upgrade is not immediately possible, review and restrict host volume delete permissions to the minimal namespaces required, ensuring that operators cannot delete claims across namespace boundaries.
  • Audit existing volume claims to identify any unintended or orphaned claims that could be affected, and adjust namespace isolation policies accordingly.

Generated by OpenCVE AI on July 26, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp nomad
Hashicorp nomad Enterprise
Vendors & Products Hashicorp
Hashicorp nomad
Hashicorp nomad Enterprise

Wed, 08 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Title Nomad vulnerable to cross-namespace host volume claim deletion
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Hashicorp Nomad Nomad Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-07-09T13:40:15.017Z

Reserved: 2026-07-06T18:35:49.618Z

Link: CVE-2026-14896

cve-icon Vulnrichment

Updated: 2026-07-09T13:40:10.321Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:15:04Z

Weaknesses