EXECUTIVE SUMMARY:
A high-severity privilege escalation vulnerability CVE-2025-4922 has been identified in the workload orchestration tool Nomad, which impacts both its Community and Enterprise editions. The flaw lies in the Access Control List (ACL) policy lookup mechanism, where a prefix-based job name matching approach can cause incorrect policy application. By crafting job names that mimic existing privileged jobs, an attacker with the appropriate access can exploit this behavior to inherit elevated permissions without explicit policy assignment. This misapplication could enable unauthorized execution of privileged workloads, posing a significant security risk to environments relying on ACLs for access governance. The vulnerability affects Nomad Community versions and Enterprise versions. It is strongly advised to upgrade to the fixed versions for Enterprise editions. The vulnerability has a CVSS score of 8.1.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A high-severity privilege escalation vulnerability CVE-2025-4922 has been identified in the workload orchestration tool Nomad, which impacts both its Community and Enterprise editions. The flaw lies in the Access Control List (ACL) policy lookup mechanism, where a prefix-based job name matching approach can cause incorrect policy application. By crafting job names that mimic existing privileged jobs, an attacker with the appropriate access can exploit this behavior to inherit elevated permissions without explicit policy assignment. This misapplication could enable unauthorized execution of privileged workloads, posing a significant security risk to environments relying on ACLs for access governance. The vulnerability affects Nomad Community versions and Enterprise versions. It is strongly advised to upgrade to the fixed versions for Enterprise editions. The vulnerability has a CVSS score of 8.1.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Nomad ACL Products to below versions:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]