CVE Explorer
CVE-2026-29194
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a route permits host authentication (hostAllowed=true), a valid host token bypasses all subsequent authorization checks without verifying that the host is authorized to access the specific requested resource. Any entity possessing knowledge of object identifiers (node IDs, host IDs) can craft a request with an arbitrary valid host token to access, modif
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"netmaker","vendor":"gravitl","versions":[{"status":"affected","version":"< 1.5.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:170982ef4d6511afd7e3e8bbd333a257d8bbf1ea4df41a4fc1ea91972dc77e5b · sha256:246c99247f99ff81… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:170982ef4d6511afd7e3e8bbd333a257d8bbf1ea4df41a4fc1ea91972dc77e5b · sha256:246c99247f99ff81… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:170982ef4d6511afd7e3e8bbd333a257d8bbf1ea4df41a4fc1ea91972dc77e5b · sha256:246c99247f99ff81… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/gravitl/netmaker/releases/tag/v1.5.0","tags":["x_refsource_MISC"],"url":"https://github.com/gravitl/netmaker/releases/tag/v1.5.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:170982ef4d6511afd7e3e8bbd333a257d8bbf1ea4df41a4fc1ea91972dc77e5b · sha256:246c99247f99ff81… · /containers/cna/references/1
{"name":"https://github.com/gravitl/netmaker/security/advisories/GHSA-hmqr-wjmj-376c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gravitl/netmaker/security/advisories/GHSA-hmqr-wjmj-376c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:170982ef4d6511afd7e3e8bbd333a257d8bbf1ea4df41a4fc1ea91972dc77e5b · sha256:246c99247f99ff81… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.