๐Ÿ” CVE Alert

CVE-2026-47726

UNKNOWN 0.0

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 โ€” handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via store.ListAuditEntries (up to limit=1000). This includes cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked-IP entries from rate-limit refusals โ€” enough surface for a tenant to enumerate the server's activity, infer staffing patterns, or identify high-value targets. This issue has been patched in version 0.3.2.

CWE CWE-285
Vendor juev
Product nebula-mesh
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for juev nebula-mesh

Be the first to know when new unknown vulnerabilities affecting juev nebula-mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

juev / nebula-mesh
< 0.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-qm33-p5p9-f8vg github.com: https://github.com/forgekeep/nebula-mesh/commit/8baaace54c2a23e7c351b3efab5a31ab07b125dc github.com: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2