Authentication Bypass Vulnerability in Netmaker by Gravitl
CVE-2026-38651

8.2HIGH

Key Information:

Vendor

Gravitl

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-38651?

An authentication bypass vulnerability exists in Netmaker versions prior to 1.5.0. The flaw is located within the VerifyHostToken function in logic/jwts.go, which inadequately validates the JWT signature when checking host tokens. This allows an attacker to forge a JWT using any arbitrary key, enabling them to impersonate any host on the network. As a result, unauthorized access to sensitive information can be gained, posing serious security risks to affected networks.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.