Session Token Exposure Vulnerability in Nebula Mesh VPN
CVE-2026-53603

7.1HIGH

Key Information:

Vendor

Forgekeep

Vendor
CVE Published:
4 September 2026

What is CVE-2026-53603?

Nebula Mesh VPN is affected by a vulnerability where operator session tokens are stored in plaintext in the database's operator_sessions table, specifically within the token column. This session token, a 32-byte random hex value, is transmitted in a cookie and remains valid for 24 hours. An attacker gaining access to the database can read the session tokens, enabling them to hijack active operator sessions without additional authentication measures. This issue has been addressed in version 0.3.8, highlighting the importance of upgrading to secure user session management.

Affected Version(s)

nebula-mesh < 0.3.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.