Token Lifetime Oversight in nebula-mesh Control Plane for Slack Nebula VPN
CVE-2026-55513
5.4MEDIUM
What is CVE-2026-55513?
In the nebula-mesh control plane for Slack Nebula VPN, versions prior to 0.5.0 contain a configuration oversight that allows the Web UI host creation process to disregard the intended token lifetime settings. Specifically, authenticated operators can create hosts via the Web UI, leading to the issuance of bearer enrollment tokens that remain valid for approximately 24 hours, irrespective of server-defined policies. This vulnerability poses a risk for deployments aiming to minimize token lifetime, as it undermines expected security parameters. The issue has been addressed in version 0.5.0.
Affected Version(s)
nebula-mesh >= 0.3.0, < 0.5.0
