Improper Certificate Validation in Netmaker by Gravitl
CVE-2026-81034

8.3HIGH

Key Information:

Vendor

Gravitl

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-81034?

Netmaker exhibits a significant security vulnerability by disabling certificate verification for connections to mail servers. The configuration bypasses essential security measures, as the TLS settings allow for unconditional acceptance of any certificates. This oversight means that sensitive information, including password reset tokens and enrollment links, could be intercepted by malicious actors. Such vulnerabilities can facilitate unauthorized access to user accounts, posing a serious threat to the security of personal data transmitted via email. Organizations using Netmaker should take immediate precautions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

netmaker 0 <= 1.6.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.