CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14978

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-08-19
A local attacker can exploit a vulnerability in Hashicorp Terraform to bypass security measures and disclose information.

CSIRTS triage

What
Local attacker can bypass security measures and disclose information in Terraform.
Who is affected
Local users on systems running affected Terraform versions.
Urgency
Medium; requires local access and no active exploitation reported.
Action
Update Terraform to patched version addressing CVE-2026-14978.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-14978

Get an email if CVE-2026-14978 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-14978

CVE.org record

Embed the live status

CVE-2026-14978 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14978 status](https://www.csirts.com/badge/CVE-2026-14978)](https://www.csirts.com/cve/CVE-2026-14978)