What is CVE-2026-47768?
CVE-2026-47768 is a vulnerability in nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN, where a newly-created operator API key is exposed in the redirect URL (Referer, history, proxy logs). This affects versions prior to 0.3.2, and users are advised to update to version 0.3.2 immediately.
Azərbaycanca: CVE-2026-47768, nebula-mesh virtual şəxsi şəbəkə idarəetmə panelində yeni yaradılan operator API açarının redirect URL-də (Referer, tarixçə, proxy logları) ifşa olunması zəifliyidir. Bu, 0.3.2 versiyasından əvvəlki versiyalara təsir edir və istifadəçilərə dərhal 0.3.2 versiyasına yenilənmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of nebula-mesh are affected by CVE-2026-47768?
CVE-2026-47768 affects all versions of nebula-mesh prior to version 0.3.2.
What is recommended for nebula-mesh users to mitigate CVE-2026-47768?
Users are advised to update nebula-mesh to version 0.3.2 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.