Improper Certificate Validation in Netmaker by Gravitl
CVE-2026-81034
8.3HIGH
What is CVE-2026-81034?
Netmaker exhibits a significant security vulnerability by disabling certificate verification for connections to mail servers. The configuration bypasses essential security measures, as the TLS settings allow for unconditional acceptance of any certificates. This oversight means that sensitive information, including password reset tokens and enrollment links, could be intercepted by malicious actors. Such vulnerabilities can facilitate unauthorized access to user accounts, posing a serious threat to the security of personal data transmitted via email. Organizations using Netmaker should take immediate precautions to mitigate potential risks associated with this vulnerability.
Affected Version(s)
netmaker 0 <= 1.6.0
