CVE-2026-14891: Nomad vulnerable to sandbox escape in Docker task driver
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Nomad (Nomad Community Edition)to a version that resolves this vulnerability.Fixed in 2.0.4Patch CVE-2026-14891 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4Patch CVE-2026-14891 - Upgrade
Upgrade
HashiCorp Nomadto a version that resolves this vulnerability.Fixed in 1.11.8Patch CVE-2026-14891 - Upgrade
Upgrade
HashiCorp Nomadto a version that resolves this vulnerability.Fixed in 1.10.14Patch CVE-2026-14891
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14891?
The severity of CVE-2026-14891 is rated as high, with a score of 8.7.
How do I fix CVE-2026-14891?
To fix CVE-2026-14891, update HashiCorp Nomad and Nomad Enterprise to the latest version where the vulnerability is patched.
What systems are affected by CVE-2026-14891?
CVE-2026-14891 affects HashiCorp Nomad and HashiCorp Nomad Enterprise when using the Docker task driver.
What are the potential impacts of CVE-2026-14891?
The potential impacts of CVE-2026-14891 include unauthorized access to host files and directories due to sandbox escape.
Who can exploit CVE-2026-14891?
A job submitter with appropriate permissions can exploit CVE-2026-14891 to bind-mount a host path into a container.