Unrestricted API Access in Netmaker Affects WireGuard Configurations
CVE-2026-29196

8.7HIGH

Key Information:

Vendor

Gravitl

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-29196?

Netmaker, a platform utilizing WireGuard for managing networks, has a security flaw that allows users assigned the platform-user role to access sensitive information, specifically retrieving the WireGuard private keys associated with all configurations within a network. This is enabled by misconfigured API endpoints that return complete records, inclusive of private keys, without proper ownership verification, despite the Netmaker UI's limitations on visibility. This significant vulnerability has been resolved with the release of version 1.5.0.

Affected Version(s)

netmaker < 1.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.