Authorization Flaw in nebula-mesh Control Plane for Slack by Forgekeep
CVE-2026-47724
9.9CRITICAL
What is CVE-2026-47724?
The nebula-mesh control plane, designed for managing Slack's Nebula mesh virtual private network, has a critical authorization flaw affecting the /api/v1/* route. Prior to version 0.3.4, this route relied solely on the bearer token for authorization, thereby exposing multiple endpoints to potential misuse by non-admin operators. This oversight allows unauthorized access across tenants, creating a significant risk of privilege escalation through specific API keys. The issue has been addressed with the release of version 0.3.4, enhancing security by implementing more stringent access controls.
Affected Version(s)
nebula-mesh < 0.3.4
