Session Management Vulnerability in Nebula Mesh Control Plane by Forgekeep
CVE-2026-48058

4.6MEDIUM

Key Information:

Vendor

Juev

Vendor
CVE Published:
28 July 2026

What is CVE-2026-48058?

Nebula Mesh, a self-hosted control plane for VPNs, has a vulnerability in its session management. Before version 0.3.2, the application failed to mark cookies as 'Secure', allowing potential exposure of session data through misconfigurations like mistyped URLs or improper HTTP to HTTPS enforcement. This flaw could permit attackers to gain unauthorized access to user sessions, especially if a plaintext request is made to the application origin. It is recommended that users upgrade to version 0.3.2 or later to mitigate this risk.

Affected Version(s)

nebula-mesh < 0.3.2

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.