Authorization Bypass in Netmaker's Host Token Validation
CVE-2026-29194
8.6HIGH
What is CVE-2026-29194?
Prior to version 1.5.0, Netmaker's Authorize middleware failed to validate host JWT tokens correctly. When configured to allow host authentication, a legitimate host token could bypass necessary authorization checks, enabling unauthorized access to resources. This vulnerability grants any entity aware of specific identifiers to craft requests using an arbitrary valid token, which could lead to the retrieval, modification, or deletion of resources from other hosts. Affected functionalities include node information retrieval and host deletion, among others, posing significant risks to the integrity of network management. This issue is addressed in version 1.5.0.
Affected Version(s)
netmaker < 1.5.0
