Junglewise Threat Intelligence

CVE-2026-49258: Nebula Mesh authorization bypass in web UI host management

CVE-2026-49258 · Severity: high · CVSS 8.8 · Published 2026-07-28

Technologies: Forgekeep Nebula-Mesh, github.com/juev/nebula-mesh (Go). Vendors: Forgekeep, Go.

Executive brief

Nebula Mesh is a management tool for Slack Nebula VPNs, allowing administrators to control secure network connections. A security flaw in the web interface allows any registered user to view, block, or delete network resources belonging to other users. This could lead to unauthorized access to sensitive network configuration data or a complete disruption of VPN services for other customers or departments.

Technical details

Nebula Mesh fails to implement per-operator Certificate Authority (CA) scoping within its web UI handlers (/ui/*), a vulnerability class previously addressed only in the JSON API. The flaw stems from missing authorization checks in several handlers, including handleHostDetail, handleHostBlock, handleHostDelete, and others, which allow an attacker to perform Insecure Direct Object Reference (IDOR) attacks by manipulating resource IDs. An authenticated attacker with low privileges (such as a self-registered user) can read host names, public IPs, and certificate details, or perform mutation actions like blocking or deleting hosts belonging to other tenants. This issue is tracked as a regression/omission from a previous fix (GHSA-598g-h2vc-h5vg) and is resolved in version 0.3.6 by unifying ownership checks under the loadAccessibleHost helper.

Affected products

  • forgekeep Nebula Mesh <= 0.3.5

Timeline

  • 2026-05-25: patched: Fix merged in pull request 161
  • 2026-07-28: disclosed: CVE-2026-49258 published

References

Related threats