In-band Isolation Vulnerability in Nebula Mesh Control Plane for Slack VPN
CVE-2026-61699
What is CVE-2026-61699?
The Nebula Mesh control plane for Slack is vulnerable to an in-band isolation issue that affects host revocation processes. Prior to version 0.7.1, hosts that were compromised or offboarded could maintain connectivity within the overlay network for extended periods, despite being removed from the configuration. This misconfiguration arises because the blocklist is not disseminated to peers, allowing blocked hosts to access internal services. Even after an operator revokes a host’s access, an attacker with the appropriate keys can bypass restrictions, remaining connected to the network. This vulnerability has been addressed in version 0.7.1, and users are recommended to upgrade to this version to enhance their network security.
Affected Version(s)
nebula-mesh < 0.7.1
