


Perceptive Security
SOC/SIEM Consultancy

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA sco…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 20:07:40
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Network Infrastructure
CVE-2026-49258 affects Nebula Mesh, a self-hosted control plane for the Slack Nebula mesh VPN, in versions 0.3.5 and below. The web UI (/ui/*) fails to apply per-operator CA scoping that the JSON API correctly enforces, leaving resources accessible across operator boundaries. This issue was only partially addressed by a prior advisory (GHSA-598g-h2vc-h5vg), as the fix was not extended to the web read and mutation surface. Any authenticated non-admin operator, including those created via self-registration or OIDC, can read, block, or delete hosts and networks belonging to other operators. Host creation, editing, mobile-bundle, network-create paths, and CA-management routes were already correctly scoped and are not affected. The vulnerability represents a broken access control issue allowing horizontal privilege escalation between operators. The issue has been fully resolved in version 0.3.6.
Technical details
Mitigation steps:
Affected products:
Nebula Mesh 0.3.5 and below
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49258
https://github.com/forgekeep/nebula-mesh/pull/161
https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-c6v2-3ffm-vcmc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
