HashiCorp has revealed a critical vulnerability in its Nomad tool that may let attackers gain higher privileges by misusing the Access Control List (ACL) policy lookup. Identified as CVE-2025-4922, this vulnerability has a CVSS score of 8.1, indicating significant risk for organizations using affected Nomad versions.
“Nomad prefix-based ACL policy lookup can lead to incorrect rule application and shadowing,” HashiCorp warned in its security advisory.
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
Nomad has an optional ACL system that controls access to jobs, data, and APIs. It’s capability-based, where users receive permissions through tokens linked to specific policies. The issue arises from Nomad’s method of matching jobs to ACL policies using prefix-based lookups.
This lookup method can be easily manipulated to implement incorrect policies by utilizing job names that share identical prefixes. For instance, a privileged job labeled test-job could inadvertently pass its policies to a less privileged job called test-job-2, resulting from the way the prefix matching operates.
“An attacker with the proper access could create a new job with a prefixed name… to inherit the same ACL policies as an already existing job,” the advisory explained. “This could allow running privileged jobs without explicitly configuring a new policy.”
The vulnerability affects both Nomad Community Edition and Nomad Enterprise, specifically:
Nomad Community from version 1.4.0 to 1.10.1
Nomad Enterprise from version 1.4.0 to 1.10.1, 1.9.9, and 1.8.13
The issue has been resolved in the following patched releases:
Community: 1.10.2
Enterprise: 1.10.2, 1.9.10, and 1.8.14
HashiCorp strongly advises users to upgrade to the fixed versions immediately.