Authorization Bypass in Netmaker's Host Token Validation
CVE-2026-29194

8.6HIGH

Key Information:

Vendor

Gravitl

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-29194?

Prior to version 1.5.0, Netmaker's Authorize middleware failed to validate host JWT tokens correctly. When configured to allow host authentication, a legitimate host token could bypass necessary authorization checks, enabling unauthorized access to resources. This vulnerability grants any entity aware of specific identifiers to craft requests using an arbitrary valid token, which could lead to the retrieval, modification, or deletion of resources from other hosts. Affected functionalities include node information retrieval and host deletion, among others, posing significant risks to the integrity of network management. This issue is addressed in version 1.5.0.

Affected Version(s)

netmaker < 1.5.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.