Junglewise Threat Intelligence

CVE-2026-14468: HashiCorp Terraform Enterprise path traversal in VCS module ingestion

CVE-2026-14468 · Severity: high · CVSS 7.7 · Published 2026-07-06

Vendors: HashiCorp.

Executive brief

HashiCorp Terraform Enterprise, a platform for managing infrastructure as code, contained a flaw in how it imports modules from version control systems. An authorized user could exploit this to trick the system into including sensitive files from the underlying server—such as configuration files or secrets—into a module package. Once the package is downloaded, the attacker can view these sensitive files, potentially leading to a broader compromise of the infrastructure management environment.

Technical details

A path traversal vulnerability (CWE-22) exists in Terraform Enterprise's Version Control System (VCS) ingestion process for registry modules. The application fails to properly validate or restrict the file boundaries when packaging repository content into a module artifact. An authenticated attacker with permissions to publish registry modules can craft a module that includes files from the host filesystem located outside the intended repository directory. If the ingestion process has read permissions for these files (such as application secrets or configuration), they are included in the downloadable module artifact. The issue is resolved in versions 2.0.4 and 1.2.4.

Affected products

  • HashiCorp Terraform Enterprise 1.0.0 through 2.0.3; v202506-1; v202507-1

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory
  • 2026-07-06: patched

References