8.2

CVE-2026-38651

Exploit
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetmakerNetmaker Version < 1.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.212
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://github.com/gravitl/netmaker/commit/5309aa70d464ef565911369714d661a61481a79b
Patch
https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass
Third Party Advisory
Exploit
https://www.zyenra.com/blog/netmaker-jwt-verification-bypass
Third Party Advisory
Exploit
https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/
Third Party Advisory
Exploit