Authorization Gaps in Nebula Mesh VPN Control Plane
CVE-2026-53602
6.9MEDIUM
What is CVE-2026-53602?
The Nebula Mesh VPN control plane faced significant security risks due to two interconnected authorization gaps present before version 0.3.7. The system failed to enforce blocklist checks during certificate issuance, allowing untrusted hosts to obtain valid Nebula certificates. Specifically, the blocklist was not consulted upon signing or re-enrolling, and the renewal process inadequately validated operator and CA status. As a result, compromised operators could still generate valid certifications without proper scrutiny. The issue has since been addressed in the latest update.
Affected Version(s)
nebula-mesh < 0.3.7
