Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196685 vulns · 37/41 feeds (7d)
← Back to list
7.7
CVE-2026-14468PATCHED
hashi · terraform enterpri

Path traversal allows arbitrary file read in Terraform Enterprise container

Description

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.

Affected Products

VendorProductVersions
hashiterraform enterpri1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hashiterraformcert_advisory90%

References

  • https://discuss.hashicorp.com/t/hcsec-2026-17-terraform-enterprise-vulnerable-to-arbitrary-file-read/77549

Related News (2 articles)

Tier B
BSI Advisories48d ago
[NEU] [mittel] Hashicorp Terraform: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier C
VulDB49d ago
CVE-2026-14468 | HashiCorp Terraform Enterprise up to 2.0.3 VCS Ingestion Boundary information disclosure
→ No new info (linked only)
CVSS 3.17.7 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.0.4
CWECWE-22
PublishedJul 6, 2026
Last enriched49d agov2
Trending Score0
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 33
CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 13
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 11
HIGHCVE-2026-19589
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Trending: 10
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 10

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 6, 2026
Discovered by ZDM
Jul 6, 2026
Updated: affectedVersions
Jul 6, 2026
Patch Available
Jul 7, 2026

Version History

v2
Last enriched 49d ago
v2Tier C49d ago

Updated affected versions to include 2.0.3 and clarified that no exploit is available.

affectedVersions
via VulDB
v149d ago

Initial creation