Authorization Gaps in Nebula Mesh VPN Control Plane
CVE-2026-53602

6.9MEDIUM

Key Information:

Vendor

Forgekeep

Vendor
CVE Published:
4 September 2026

What is CVE-2026-53602?

The Nebula Mesh VPN control plane faced significant security risks due to two interconnected authorization gaps present before version 0.3.7. The system failed to enforce blocklist checks during certificate issuance, allowing untrusted hosts to obtain valid Nebula certificates. Specifically, the blocklist was not consulted upon signing or re-enrolling, and the renewal process inadequately validated operator and CA status. As a result, compromised operators could still generate valid certifications without proper scrutiny. The issue has since been addressed in the latest update.

Affected Version(s)

nebula-mesh < 0.3.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.