Session Token Exposure Vulnerability in Nebula Mesh VPN
CVE-2026-53603
7.1HIGH
What is CVE-2026-53603?
Nebula Mesh VPN is affected by a vulnerability where operator session tokens are stored in plaintext in the database's operator_sessions table, specifically within the token column. This session token, a 32-byte random hex value, is transmitted in a cookie and remains valid for 24 hours. An attacker gaining access to the database can read the session tokens, enabling them to hijack active operator sessions without additional authentication measures. This issue has been addressed in version 0.3.8, highlighting the importance of upgrading to secure user session management.
Affected Version(s)
nebula-mesh < 0.3.8
