


Perceptive Security
SOC/SIEM Consultancy

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signatur…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:20
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access
A critical authentication bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to properly validate JWT signatures when verifying host tokens. This flaw allows attackers to forge JWT tokens signed with arbitrary keys to impersonate any host in the network. Successful exploitation grants unauthorized access to sensitive information within the Netmaker network infrastructure. The vulnerability affects the core authentication mechanism of the Netmaker network management platform.
Technical details
Mitigation steps:
Affected products:
Netmaker
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-38651
https://github.com/gravitl/netmaker/commit/5309aa70d464ef565911369714d661a61481a79b
https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass
https://www.zyenra.com/blog/netmaker-jwt-verification-bypass
https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/
https://www.zyenra.com/blog/netmaker-jwt-verification-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
