Medium severity6.1NVD Advisory· Published Aug 16, 2026
CVE-2026-74796
CVE-2026-74796
Description
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.