CVE-2026-8052 PUBLISHED

Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack

Assigner: HashiCorp
Reserved: 06.05.2026 Published: 12.05.2026 Updated: 12.05.2026

HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
CVSS Score: 6

Product Status

Vendor HashiCorp
Product Shared library
Versions Default: unaffected
  • affected from 0.1.0 to 0.1.2 (excl.)

Credits

  • This issue was identified by the Nomad engineering team in conjunction with Alex Manson (Aiven / NeuroWinter).

References

Problem Types

  • CWE-59: Improper Link Resolution Before File Access (Link Following) CWE

Impacts

  • CAPEC-132: Symlink Attack