What is CVE-2026-74796?
CVE-2026-74796 is a vulnerability in OpenTofu versions prior to 1.11.7 where existing symlinks in the provider cache directory are not validated during initialization. An attacker can place a malicious symlink in a trusted working directory, causing 'tofu init' to write provider package contents to arbitrary filesystem locations outside the working tree. Immediate upgrade to OpenTofu 1.11.7 or later is required.
Azərbaycanca: CVE-2026-74796 OpenTofu 1.11.7 öncəsi versiyalarda provider cache qovluğunda mövcud simvolik keçidlərin (symlink) yoxlanılmaması zəifliyidir. Təcavüzkar etibarlı iş qovluğuna zərərli symlink yerləşdirərək 'tofu init' əmri ilə fayl sistemi üzərində ixtiyari yerlərə yazmağa nail ola bilər. Dərhal OpenTofu 1.11.7 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What is the CVE-2026-74796 vulnerability?
CVE-2026-74796 is a vulnerability in OpenTofu versions prior to 1.11.7 where existing symlinks in the provider cache directory are not validated during initialization. An attacker can place a malicious symlink in a trusted working directory, causing 'tofu init' to write provider package contents to arbitrary filesystem locations outside the working tree.
How to protect against CVE-2026-74796?
Immediate upgrade to OpenTofu 1.11.7 or later is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.