CVE-2026-74796
Severity CVSS v4.0:
HIGH
Type:
CWE-59
Link Following
Publication date:
16/08/2026
Last modified:
16/08/2026
Description
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.10
Severity 3.x
MEDIUM



