Junglewise Threat Intelligence

CVE-2026-38651: Gravitl Netmaker authentication bypass in VerifyHostToken

CVE-2026-38651 · Severity: high · CVSS 8.2 · Published 2026-04-28

Technologies: Netmaker, github.com/gravitl/netmaker (Go). Vendors: Netmaker, Go.

Executive brief

Netmaker, a platform for managing virtual overlay networks, contains a security flaw that allows unauthorized users to bypass authentication. By creating a specially crafted security token, an attacker can impersonate any device on the network. This could lead to the theft of sensitive configuration data, including encrypted passwords and network keys, potentially compromising the entire virtual network.

Technical details

An authentication bypass exists in Netmaker's 'VerifyHostToken' function within 'logic/jwts.go'. The implementation uses the 'golang-jwt/jwt' library but fails to check the 'token.Valid' field or the returned error after calling 'ParseWithClaims'; it only verifies that the token object itself is non-nil. Consequently, any structurally valid JWT signed with an arbitrary key is accepted. An unauthenticated remote attacker can exploit this to impersonate any host ID and access sensitive endpoints such as '/api/v1/host', which returns bcrypt-hashed passwords, MQTT credentials, and WireGuard peer data. The issue is resolved in version 1.5.0 by properly validating the token state.

Affected products

  • Gravitl Netmaker < 1.5.0

Timeline

  • 2026-01-22: disclosed: Vulnerability reported to vendor
  • 2026-02-24: patched: Fixed in commit 5309aa70
  • 2026-04-28: advisory: CVE published

References

Related threats