CVE-2026-14896: Nomad vulnerable to cross-namespace host volume claim deletion
HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.4 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.11.8 - Upgrade
Upgrade
HashiCorp Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.10.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14896?
CVE-2026-14896 has a medium severity rating of 4.2.
What systems are affected by CVE-2026-14896?
CVE-2026-14896 affects HashiCorp Nomad and HashiCorp Nomad Enterprise.
What type of vulnerability is CVE-2026-14896?
CVE-2026-14896 is a cross-namespace authorization bypass vulnerability.
How can CVE-2026-14896 be mitigated?
To mitigate CVE-2026-14896, ensure strict access controls and policies are in place to manage host volume permissions across namespaces.
What potential impact does CVE-2026-14896 have?
CVE-2026-14896 may allow unauthorized deletion of sticky volume claims across different namespaces.