In-band Isolation Vulnerability in Nebula Mesh Control Plane for Slack VPN
CVE-2026-61699

8.1HIGH

Key Information:

Vendor

Forgekeep

Vendor
CVE Published:
4 September 2026

What is CVE-2026-61699?

The Nebula Mesh control plane for Slack is vulnerable to an in-band isolation issue that affects host revocation processes. Prior to version 0.7.1, hosts that were compromised or offboarded could maintain connectivity within the overlay network for extended periods, despite being removed from the configuration. This misconfiguration arises because the blocklist is not disseminated to peers, allowing blocked hosts to access internal services. Even after an operator revokes a host’s access, an attacker with the appropriate keys can bypass restrictions, remaining connected to the network. This vulnerability has been addressed in version 0.7.1, and users are recommended to upgrade to this version to enhance their network security.

Affected Version(s)

nebula-mesh < 0.7.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.