Authentication Bypass Vulnerability in Netmaker by Gravitl
CVE-2026-38651
8.2HIGH
What is CVE-2026-38651?
An authentication bypass vulnerability exists in Netmaker versions prior to 1.5.0. The flaw is located within the VerifyHostToken function in logic/jwts.go, which inadequately validates the JWT signature when checking host tokens. This allows an attacker to forge a JWT using any arbitrary key, enabling them to impersonate any host on the network. As a result, unauthorized access to sensitive information can be gained, posing serious security risks to affected networks.
