Incorrect authorization in Netmaker - CVE-2026-29196

 

Incorrect authorization in Netmaker - CVE-2026-29196

Published: April 27, 2026


Vulnerability identifier: #VU128021
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29196
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in GET /api/extclients/{network} and GET /api/nodes/{network} when handling requests for network configuration records. A remote user can send a crafted API request to disclose sensitive information.

The issue exposes WireGuard private keys from wireguard configs across the network because returned records are not filtered based on the requesting user's ownership.


Affected software

Netmaker

How to mitigate CVE-2026-29196

Install security update from vendor's website.

Netmaker - update to 1.5.0

External References

Related Security Bulletins