CVE-2026-8052
MEDIUMNomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
Title source: cnaDescription
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.
Scores
CVSS v3
6.0
EPSS
0.0003
EPSS Percentile
8.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-59
Status
published
Products (2)
hashicorp/nomad-driver-exec2
0 - 0.1.2Go
HashiCorp/Shared library
0.1.0 - 0.1.2
Published
May 12, 2026
Tracked Since
May 13, 2026