Authorization Flaw in Nebula-Mesh Control Plane for Slack
CVE-2026-47726
7.1HIGH
What is CVE-2026-47726?
The Nebula-Mesh control plane for Slack is affected by an authorization flaw that allows users with any operator API key to access the full audit log. This log contains sensitive information, including cross-tenant actor names, timestamps, host identifiers, and masked IP addresses related to rate-limit refusals. Without sufficient admin checks in place, any operator can enumerate the server's activities, potentially compromising user privacy and operational security. This flaw was corrected in version 0.3.2, closing the loophole to protect tenant data from unwanted exposure.
Affected Version(s)
nebula-mesh < 0.3.2
