Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
05 / REFERENCES
Further evidence
- https://discuss.hashicorp.com/t/hcsec-2025-12-nomad-vulnerable-to-incorrect-acl-policy-lookup-attached-to-a-job/75396
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4922.json
- https://github.com/hashicorp/nomad
- https://nvd.nist.gov/vuln/detail/CVE-2025-4922
- https://github.com/advisories/GHSA-rx97-6c62-55mf