What is CVE-2026-48025?
CVE-2026-48025 is a vulnerability in nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN, where an ed25519 private key is stored in plaintext within CAManager after unwrapping by the master key. This may lead to exposure of sensitive key material. Users are advised to upgrade to version 0.3.7 or later.
Azərbaycanca: CVE-2026-48025 zəifliyi Slack Nebula mesh VPN üçün öz-özünə host edilən nebula-mesh idarə panelində aşkar edilmişdir. Bu boşluq master açarı ilə açıldıqdan sonra ed25519 şəxsi açarının düz mətn şəklində CAManager daxilində saxlanılması səbəbindən həssas kalit məlumatlarının ifşasına yol aça bilər. İstifadəçilərə bu problemi aradan qaldıran 0.3.7 və ya daha yeni versiyaya yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: Slack
FAQ2
In which component of nebula-mesh was CVE-2026-48025 discovered?
CVE-2026-48025 was discovered in the CAManager component of the nebula-mesh control plane.
What version are users advised to upgrade to in order to fix CVE-2026-48025?
Users are advised to upgrade to version 0.3.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.