What is CVE-2026-47723?
CVE-2026-47723 affects the nebula-mesh self-hosted control plane by failing to set critical browser security headers like Content-Security-Policy and X-Frame-Options in web and API responses. This exposes users to client-side attacks such as clickjacking and cross-site scripting (XSS) prior to version 0.3.1, where the fix should be applied.
Azərbaycanca: CVE-2026-47723, özəl şəbəkə idarəetmə paneli olan nebula-mesh-in veb API-lərində standart brauzer təhlükəsizlik başlıqlarının (Content-Security-Policy, X-Frame-Options) qurulmaması səbəbindən istifadəçiləri clickjacking, XSS kimi müştəri tərəfli hücumlara qarşı həssas buraxır. 0.3.1 versiyasına qədər təsirlidir, yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ1
How to protect against CVE-2026-47723?
The vulnerability exists in nebula-mesh prior to version 0.3.1, so updating to at least version 0.3.1 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.