CVE Vulnerabilities

CVE-2025-4922

Incorrect Privilege Assignment

Published: Jun 11, 2025 | Modified: Dec 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp1.4.0 (including)1.8.14 (excluding)
NomadHashicorp1.4.0 (including)1.10.2 (excluding)
NomadHashicorp1.9.0 (including)1.9.10 (excluding)
NomadHashicorp1.10.0 (including)1.10.2 (excluding)

Potential Mitigations

References