CVE-2023-1782: Hashicorp Nomad
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Affected products
- Hashicorp Nomad: from 1.5.0, up to and including 1.5.2
Published 2023-04-05. Last modified 2026-06-17.