CVE-2026-74796: OpenTofu before 1.11.7 Symlink Following Path Traversal
Published Aug 16, 2026
·Updated
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Affected Software
1 affected component
OpenTofu<1.11.7
Event History
Aug 16, 2026
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74796?
CVE-2026-74796 has a medium severity rating of 6.1.
2
How do I fix CVE-2026-74796?
To fix CVE-2026-74796, upgrade to OpenTofu version 1.11.7 or later.
3
What effect does CVE-2026-74796 have on OpenTofu?
CVE-2026-74796 allows attackers to manipulate symlinks, leading to arbitrary file writes outside of the working tree.
4
Who is affected by CVE-2026-74796?
Any users of OpenTofu prior to version 1.11.7 are affected by CVE-2026-74796.
5
What can attackers achieve with CVE-2026-74796?
Attackers can use CVE-2026-74796 to write provider package contents to arbitrary filesystem locations, posing a security risk.