What is CVE-2026-48058?
CVE-2026-48058 is a vulnerability in nebula-mesh, a self-hosted VPN control plane, where cookies lacked the 'Secure' attribute before version 0.3.2. This allows session hijacking via plaintext requests on a local network. Users should upgrade to version 0.3.2 immediately.
Azərbaycanca: CVE-2026-48058, nebula-mesh şəxsi virtual şəbəkə idarəetmə platformasında aşkarlanmış boşluqdur. 0.3.2 versiyasından əvvəl "Secure" atributu olmayan kukilər açıq mətnli sorğular vasitəsilə oğurlana bilər, bu da lokal şəbəkədəki təcavüzkarın sessiyanı ələ keçirməsinə imkan verir. İstifadəçilər dərhal 0.3.2 versiyasına yeniləməlidir.
FAQ2
What issue does CVE-2026-48058 cause in the nebula-mesh platform?
The vulnerability allows cookies lacking the 'Secure' attribute to be stolen via plaintext requests, enabling an attacker on the local network to hijack the session.
What should users do to protect against CVE-2026-48058?
Users should immediately upgrade the nebula-mesh platform to version 0.3.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.