๐Ÿ” CVE Alert

CVE-2026-46484

HIGH 8.1

Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.

CWE CWE-22 CWE-285
Vendor tale
Product headplane
Published Jun 8, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for tale headplane

Be the first to know when new high vulnerabilities affecting tale headplane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

tale / headplane
< 0.6.3 >= 0.7.0-beta.1, < 0.7.0-beta.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tale/headplane/security/advisories/GHSA-vgj6-hcf2-fqf6 github.com: https://github.com/tale/headplane/releases/tag/v0.6.3 github.com: https://github.com/tale/headplane/releases/tag/v0.7.0-beta.3