CVE-2026-14373: Nomad Docker driver Linux host namespace bypass
HashiCorp Nomad and Nomad Enterprise did not enforce the allowprivileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Nomad (Community Edition)to a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.11.8 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.10.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14373?
The severity of CVE-2026-14373 is rated as high with a CVSS score of 7.7.
How do I fix CVE-2026-14373?
To fix CVE-2026-14373, ensure that the allow_privileged restriction is correctly enforced for the Docker task driver's host namespace mode options.
What systems are affected by CVE-2026-14373?
CVE-2026-14373 affects both HashiCorp Nomad and HashiCorp Nomad Enterprise.
What risks are associated with CVE-2026-14373?
CVE-2026-14373 allows an authenticated job submitter to access information in the host namespace, which can compromise security.
What is the exploit vector for CVE-2026-14373?
The exploit vector for CVE-2026-14373 is through the Docker task driver's host namespace configuration options.