Improper Role Validation in Netmaker by Gravitl Allows Admins to Escalate Privileges
CVE-2026-29195
6.9MEDIUM
What is CVE-2026-29195?
In Netmaker, a networking tool that utilizes WireGuard, there exists a significant flaw in the user update handler (PUT /api/users/{username) that permits admins to erroneously assign the super-admin role during account updates. Despite the system's successful blocking of an admin from modifying another user's admin role, it fails to enforce similar restrictions for the super-admin role. This lack of validation poses a risk that could lead to unauthorized privilege escalation. The vulnerability has been adequately addressed in version 1.5.0.
Affected Version(s)
netmaker < 1.5.0
