Improper Role Validation in Netmaker by Gravitl Allows Admins to Escalate Privileges
CVE-2026-29195

6.9MEDIUM

Key Information:

Vendor

Gravitl

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-29195?

In Netmaker, a networking tool that utilizes WireGuard, there exists a significant flaw in the user update handler (PUT /api/users/{username) that permits admins to erroneously assign the super-admin role during account updates. Despite the system's successful blocking of an admin from modifying another user's admin role, it fails to enforce similar restrictions for the super-admin role. This lack of validation poses a risk that could lead to unauthorized privilege escalation. The vulnerability has been adequately addressed in version 1.5.0.

Affected Version(s)

netmaker < 1.5.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.