CVE-2026-6959: Hashicorp Nomad
Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Affected products
- Hashicorp Nomad: from 0.9.0, before 2.0.1 (fixed in 2.0.1)
- Hashicorp Nomad Enterprise: from 0.9.0, before 2.0.1 (fixed in 2.0.1)
Published 2026-05-12. Last modified 2026-06-17.