Junglewise Threat Intelligence

CVE-2026-47726: juev nebula-mesh improper authorization in audit log endpoint

CVE-2026-47726 · Severity: high · CVSS 4 · Published 2026-07-28

Technologies: Juev Nebula-Mesh, github.com/juev/nebula-mesh (Go). Vendors: Go.

Executive brief

Nebula-mesh is a control plane for managing Slack Nebula virtual private networks. A security flaw allowed any registered user with an API key to view the entire system's audit logs, which are normally restricted to administrators. This could allow unauthorized users to see sensitive activity across the entire network, including staffing patterns and the identities of high-value targets.

Technical details

An improper authorization vulnerability (CWE-285) exists in the `handleGetAuditLog` function within `internal/api/audit.go`. The endpoint was protected only by a bearer-auth gate, meaning any valid operator API key could retrieve up to 1,000 audit entries via `store.ListAuditEntries`. These logs contain sensitive metadata including cross-tenant actor names, host/CA/operator IDs, and action timestamps. An attacker with low-privileged access could use this information to enumerate server activity and identify high-value targets. The issue is resolved in version 0.3.2 by implementing an `actorIsAdmin` check on the affected route.

Affected products

  • juev nebula-mesh < 0.3.2

Timeline

  • 2026-05-20: patched: Fix committed to repository
  • 2026-05-21: advisory: GitHub Security Advisory published
  • 2026-07-28: disclosed: CVE published to NVD

References

Related threats