Session Management Vulnerability in Nebula Mesh Control Plane by Forgekeep
CVE-2026-48058
4.6MEDIUM
What is CVE-2026-48058?
Nebula Mesh, a self-hosted control plane for VPNs, has a vulnerability in its session management. Before version 0.3.2, the application failed to mark cookies as 'Secure', allowing potential exposure of session data through misconfigurations like mistyped URLs or improper HTTP to HTTPS enforcement. This flaw could permit attackers to gain unauthorized access to user sessions, especially if a plaintext request is made to the application origin. It is recommended that users upgrade to version 0.3.2 or later to mitigate this risk.
Affected Version(s)
nebula-mesh < 0.3.2
