🔐 CVE Alert

CVE-2026-32599

UNKNOWN 0.0

Netmaker has a boolean‑based SQL Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform boolean-based SQL injection. Version 1.5.0 fixes the issue.

CWE CWE-89
Vendor gravitl
Product netmaker
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for gravitl netmaker

Be the first to know when new unknown vulnerabilities affecting gravitl netmaker are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

gravitl / netmaker
< 1.5.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75 github.com: https://github.com/gravitl/netmaker/releases/tag/v1.5.0