CVE-2026-7474: Hashicorp Nomad
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Affected products
- Hashicorp Nomad: from 1.10.0, before 2.0.1 (fixed in 2.0.1)
- Hashicorp Nomad Enterprise: from 1.10.0, before 2.0.1 (fixed in 2.0.1)
Published 2026-05-12. Last modified 2026-06-17.