Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6959

Опубликовано: 12 мая 2026
Источник: debian
EPSS Низкий

Описание

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nomadremovedpackage

EPSS

Процентиль: 7%
0.00169
Низкий

Связанные уязвимости

CVSS3: 6
ubuntu
3 месяца назад

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

CVSS3: 6
nvd
3 месяца назад

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

CVSS3: 6
github
3 месяца назад

HashiCorp Nomad vulnerable to symlink attack

CVSS3: 6
fstec
3 месяца назад

Уязвимость оркестратора приложений Nomad, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

CVSS3: 6
redos
25 дней назад

Уязвимость nomad

EPSS

Процентиль: 7%
0.00169
Низкий