CVE-2026-14468: Path traversal allows arbitrary file read in Terraform Enterprise container
HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Terraform Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
HashiCorp Terraform Enterpriseto a version that resolves this vulnerability.Fixed in 1.2.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14468?
The severity of CVE-2026-14468 is rated high with a score of 7.7.
What type of vulnerability is CVE-2026-14468?
CVE-2026-14468 is classified as a path traversal vulnerability.
How do I fix CVE-2026-14468?
To mitigate CVE-2026-14468, ensure that you are using the latest version of HashiCorp Terraform Enterprise that addresses this issue.
Who is affected by CVE-2026-14468?
CVE-2026-14468 affects users of HashiCorp Terraform Enterprise who utilize its version control system for registry modules.
What kind of attack can occur due to CVE-2026-14468?
CVE-2026-14468 allows an authenticated user to perform arbitrary file reads from outside the intended repository content.