CVE-2026-74796

HIGH CVSS 4.0: 7.0 EPSS 0.23%
Updated Aug 17, 2026
OpenTofu
Parameter Value
CVSS 7.0 (HIGH)
Affected Versions before 1.11.7
Type CWE-59 (Improper Link Resolution)
Vendor OpenTofu
Public PoC No

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0