Slack vulnerabilities
7 CVEs tracked
During the reporting period, Slack appeared primarily in the context of multiple critical vulnerabilities in its 'nebula-mesh' product, a self-hosted control plane for the Slack Nebula VPN. Key issues identified include template injection (CVE-2026-47722), missing authorization checks (CVE-2026-47724, CVE-2026-47726), plaintext storage of a private key (CVE-2026-48025), and missing security headers (CVE-2026-47723). Additionally, CVE-2026-35219 affects Slack integration steps within the Budibase platform. Defenders should prioritize immediate upgrades to the latest versions for nebula-mesh environments, focusing on enforcing network-level controls and monitoring for exploitation of weak authentication mechanisms.
Azərbaycanca: Hesabat dövründə Slack, əsasən öz-özünə host edilən (self-hosted) Nebula Mesh VPN idarəetmə paneli olan 'nebula-mesh' məhsulundakı çoxsayda kritik boşluqlar kontekstində görünür. Aşkarlanan əsas zəifliklərə şablon inyeksiyası (CVE-2026-47722), çatışmayan avtorizasiya yoxlamaları (CVE-2026-47724, CVE-2026-47726), düz mətn (plaintext) şəklində saxlanılan özəl açar (CVE-2026-48025) və təhlükəsizlik başlıqlarının olmaması (CVE-2026-47723) daxildir. Bundan əlavə, Budibase platformasında Slack inteqrasiya addımlarını təsir edən CVE-2026-35219 boşluğu qeyd edilir. Müdafiəçilər 'nebula-mesh' istifadə edən mühitlərdə bu boşluqların aradan qaldırılması üçün dərhal ən son versiyalara yüksəltməyə, xüsusilə şəbəkə səviyyəsində nəzarətin gücləndirilməsinə və zəif autentifikasiya mexanizmlərinin monitorinqinə diqqət yetirməlidir.
This vendor's CVEs7
This hub is built from skopnix's own reporting on Slack: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.