Authorization Flaw in Nebula-Mesh Control Plane for Slack
CVE-2026-47726

7.1HIGH

Key Information:

Vendor

Juev

Vendor
CVE Published:
28 July 2026

What is CVE-2026-47726?

The Nebula-Mesh control plane for Slack is affected by an authorization flaw that allows users with any operator API key to access the full audit log. This log contains sensitive information, including cross-tenant actor names, timestamps, host identifiers, and masked IP addresses related to rate-limit refusals. Without sufficient admin checks in place, any operator can enumerate the server's activities, potentially compromising user privacy and operational security. This flaw was corrected in version 0.3.2, closing the loophole to protect tenant data from unwanted exposure.

Affected Version(s)

nebula-mesh < 0.3.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.