CVE-2026-8052: Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Nomad exec2 task driverto a version that resolves this vulnerability.Fixed in 0.1.2Patch CVE-2026-8052
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8052?
CVE-2026-8052 is classified as a high-severity vulnerability due to its potential for arbitrary file read and write on client hosts.
How do I fix CVE-2026-8052?
To mitigate CVE-2026-8052, upgrade to HashiCorp Nomad exec2 task driver version 0.1.2 or later.
What systems are affected by CVE-2026-8052?
CVE-2026-8052 affects HashiCorp Nomad exec2 task driver versions prior to 0.1.2.
What type of attack is associated with CVE-2026-8052?
CVE-2026-8052 is associated with a symlink attack that allows arbitrary file access on the client host.
Who is the vendor for the affected product of CVE-2026-8052?
The vendor for the affected product related to CVE-2026-8052 is HashiCorp.