A vulnerability marked as problematic has been reported in OpenTofu up to 1.11.6. This vulnerability affects unknown code of the component Symlink Validation. Performing a manipulation results in link following.

This vulnerability is known as CVE-2026-74796. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.