← back
CVE-2026-7474highCWE-22

Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 6.9%
exploitation probability
6.9%top 7% of all CVEs
observed exploitation
nono source reports it
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H