
CVE-2026-6959 HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attac… https://www.cve.org/CVERecord?id=CVE-2026-6959
Post summary
The post discloses that CVE-2026-6959 allows arbitrary file read/write via symlink attacks on HashiCorp Nomad prior to version 2.0.1, but does not provide a PoC, exploit, active exploitation claim, or patch guidance.
