CVE-2026-32599
Netmaker has a boolean‑based SQL Injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform boolean-based SQL injection. Version 1.5.0 fixes the issue.
| CWE | CWE-89 |
| Vendor | gravitl |
| Product | netmaker |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for gravitl netmaker
Be the first to know when new unknown vulnerabilities affecting gravitl netmaker are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
gravitl / netmaker
< 1.5.0