top of page
perceptive_background_267k.jpg

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA sco…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 20:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Network Infrastructure

CVE-2026-49258 affects Nebula Mesh, a self-hosted control plane for the Slack Nebula mesh VPN, in versions 0.3.5 and below. The web UI (/ui/*) fails to apply per-operator CA scoping that the JSON API correctly enforces, leaving resources accessible across operator boundaries. This issue was only partially addressed by a prior advisory (GHSA-598g-h2vc-h5vg), as the fix was not extended to the web read and mutation surface. Any authenticated non-admin operator, including those created via self-registration or OIDC, can read, block, or delete hosts and networks belonging to other operators. Host creation, editing, mobile-bundle, network-create paths, and CA-management routes were already correctly scoped and are not affected. The vulnerability represents a broken access control issue allowing horizontal privilege escalation between operators. The issue has been fully resolved in version 0.3.6.

Technical details

Mitigation steps:

Affected products:

Nebula Mesh 0.3.5 and below

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page