CVE-2026-47726: CWE-285: Improper Authorization in juev nebula-mesh
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via store.ListAuditEntries (up to limit=1000). This includes cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked-IP entries from rate-limit refusals — enough surface for a tenant to enumerate the server's activity, infer staffing patterns, or identify high-value targets. This issue has been patched in version 0.3.2.
AI Analysis
Technical Summary
The vulnerability in juev nebula-mesh arises from the handleGetAuditLog endpoint in internal/api/audit.go not enforcing an administrative authorization check. Instead, it relies solely on bearer token authentication with operator API keys, which grants access to the full audit log data. This log includes sensitive cross-tenant information that could be used to enumerate server activity and infer operational details. The flaw is addressed by patching in version 0.3.2.
Potential Impact
An attacker with any operator API key can retrieve up to 1000 audit log entries containing cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked IPs related to rate-limit refusals. This exposure can lead to information disclosure that may allow an attacker to map server activity, identify staffing patterns, or pinpoint high-value targets within the environment.
Mitigation Recommendations
A fix for this vulnerability is available in juev nebula-mesh version 0.3.2. Users should upgrade to version 0.3.2 or later to ensure proper administrative authorization checks are enforced on the audit log endpoint. No other mitigation guidance is provided or necessary as the issue is resolved by this update.
CVE-2026-47726: CWE-285: Improper Authorization in juev nebula-mesh
Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via store.ListAuditEntries (up to limit=1000). This includes cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked-IP entries from rate-limit refusals — enough surface for a tenant to enumerate the server's activity, infer staffing patterns, or identify high-value targets. This issue has been patched in version 0.3.2.
CVSS v4.0
Score 7.1high
Affected software
juev
nebula-mesh
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in juev nebula-mesh arises from the handleGetAuditLog endpoint in internal/api/audit.go not enforcing an administrative authorization check. Instead, it relies solely on bearer token authentication with operator API keys, which grants access to the full audit log data. This log includes sensitive cross-tenant information that could be used to enumerate server activity and infer operational details. The flaw is addressed by patching in version 0.3.2.
Potential Impact
An attacker with any operator API key can retrieve up to 1000 audit log entries containing cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked IPs related to rate-limit refusals. This exposure can lead to information disclosure that may allow an attacker to map server activity, identify staffing patterns, or pinpoint high-value targets within the environment.
Mitigation Recommendations
A fix for this vulnerability is available in juev nebula-mesh version 0.3.2. Users should upgrade to version 0.3.2 or later to ensure proper administrative authorization checks are enforced on the audit log endpoint. No other mitigation guidance is provided or necessary as the issue is resolved by this update.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T21:29:25.483Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a68f3749c2644c7f803d823
Added to database: 07/28/2026, 18:22:44 UTC
Last enriched: 07/29/2026, 15:40:04 UTC
Last updated: 09/11/2026, 07:31:53 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.