Executive brief
HashiCorp Nomad, a tool used to manage and schedule applications across servers, contains a security flaw in how it handles storage volume permissions. An authorized user with permission to manage storage in one project (namespace) could delete storage assignments belonging to a different project. While this does not expose data, it can disrupt operations by causing applications to lose their connection to specific persistent data when they are restarted or moved.
Technical details
A cross-namespace authorization bypass (CWE-863) exists in Nomad's dynamic host volumes feature. The vulnerability stems from a failure to consistently verify that a sticky volume claim targeted for deletion belongs to the same namespace as the authenticated requester. An attacker must be an authenticated operator with 'host volume delete' permissions in at least one namespace. By exploiting this, the attacker can delete volume claims in other namespaces, which impacts scheduling correctness; when affected allocations are rescheduled or updated, they may fail to reconnect to the correct host volume. The issue is fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Affected products
- HashiCorp Nomad 0.4.1 up to 2.0.3
- HashiCorp Nomad Enterprise 0.4.1 up to 2.0.3; 1.11.0 up to 1.11.7; 1.10.0 up to 1.10.13
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched
- 2026-07-08: advisory