Token Lifetime Oversight in nebula-mesh Control Plane for Slack Nebula VPN
CVE-2026-55513

5.4MEDIUM

Key Information:

Vendor

Forgekeep

Vendor
CVE Published:
4 September 2026

What is CVE-2026-55513?

In the nebula-mesh control plane for Slack Nebula VPN, versions prior to 0.5.0 contain a configuration oversight that allows the Web UI host creation process to disregard the intended token lifetime settings. Specifically, authenticated operators can create hosts via the Web UI, leading to the issuance of bearer enrollment tokens that remain valid for approximately 24 hours, irrespective of server-defined policies. This vulnerability poses a risk for deployments aiming to minimize token lifetime, as it undermines expected security parameters. The issue has been addressed in version 0.5.0.

Affected Version(s)

nebula-mesh >= 0.3.0, < 0.5.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.