What is CVE-2026-49258?
CVE-2026-49258 is a privilege restriction vulnerability in the web UI of Nebula Mesh, a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) fails to apply the per-operator CA scoping used by the JSON API, potentially allowing operators to bypass intended restrictions. Upgrading to the latest version is recommended.
Azərbaycanca: CVE-2026-49258 Nebula Mesh-in web UI interfeysində aşkarlanmış səlahiyyət məhdudiyyəti zəifliyidir. 0.3.5 və daha aşağı versiyalarda, web UI (/ui/*) JSON API-də tətbiq olunan per-operator CA əhatə dairəsi məhdudiyyətini tətbiq etmir, bu da operatorların səlahiyyətlərini aşmasına səbəb ola bilər. Qurğunun ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Nebula Mesh are affected by CVE-2026-49258?
CVE-2026-49258 affects Nebula Mesh versions 0.3.5 and below.
In which Nebula Mesh component does CVE-2026-49258 reside, and what is its root cause?
The vulnerability resides in the web UI (/ui/*) component of Nebula Mesh. The root cause is that the web UI fails to apply the per-operator CA scoping restriction enforced by the JSON API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.