What is CVE-2026-47724?
CVE-2026-47724 affects nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN. Before version 0.3.4, the `/api/v1/*` endpoints rely solely on the bearer token for authorization, creating a security gap. Users should update to version 0.3.4 or later immediately.
Azərbaycanca: CVE-2026-47724, Slack Nebula mesh VPN üçün self-hosted idarəetmə paneli olan nebula-mesh-də aşkarlanıb. 0.3.4-dən əvvəlki versiyalarda, `/api/v1/*` marşrutları avtorizasiya üçün yalnız bearer tokenə etibar edir ki, bu da təhlükəsizlik boşluğuna səbəb olur. İstifadəçilər dərhal 0.3.4 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What product is affected by CVE-2026-47724?
CVE-2026-47724 affects nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN.
Which version should users upgrade to in order to fix CVE-2026-47724?
Users should update nebula-mesh to version 0.3.4 or later to address this security gap.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.