Junglewise Threat Intelligence

CVE-2026-47723: juev nebula-mesh missing security headers in Web UI and API

CVE-2026-47723 · Severity: high · CVSS 4 · Published 2026-07-23

Technologies: Juev Nebula-Mesh, github.com/juev/nebula-mesh (Go). Vendors: Forgekeep, Go.

Executive brief

nebula-mesh is a management tool for Slack Nebula virtual private networks, used to manage security certificates and user access. A security flaw was found where the application's web interface failed to use standard browser security protections. This could allow attackers to perform clickjacking attacks, where an administrator is tricked into performing unintended actions like deleting users or changing security settings, or lead to the exposure of sensitive information like API keys and security codes.

Technical details

nebula-mesh prior to version 0.3.1 lacks essential HTTP security headers across all response paths in its web and API components. Specifically, the absence of X-Frame-Options and Content-Security-Policy (frame-ancestors) makes the admin UI vulnerable to clickjacking, which is particularly critical as the interface handles CA certificate signing and API key generation. Additionally, the lack of X-Content-Type-Options allows for potential MIME confusion attacks, and the absence of Strict-Transport-Security (HSTS) leaves the application susceptible to protocol downgrade attacks. The vulnerability was addressed in version 0.3.1 by implementing a middleware that applies these headers to all responses.

Affected products

  • juev nebula-mesh < 0.3.1

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-20: patched: Version 0.3.1 released
  • 2026-07-23: disclosed: CVE-2026-47723 published to NVD

References

Related threats