SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14896

MEDIUM · CVSS 4.2 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

HashiCorp Nomad and Nomad Enterprise are susceptible to a cross-namespace authorization bypass in their dynamic host volumes feature, enabling operators with delete permissions in one namespace to inadvertently delete sticky volume claims in another. This vulnerability could lead to unauthorized data loss or disruption of services across different namespaces. Organizations using these versions of Nomad should prioritize applying the fixes in Community Edition 2.0.4 and Enterprise versions 2.0.4, 1.11.8, or 1.10.14 to mitigate potential risks.

CVE
CVE-2026-14896
Severity
MEDIUM
CVSS
4.2
EPSS
0.16%

Original NVD Description

HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.