CVE-2026-38651

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
Configurations

Configuration 1 (hide)

cpe:2.3:a:netmaker:netmaker:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-28 16:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-38651

Mitre link : CVE-2026-38651

CVE.ORG link : CVE-2026-38651


JSON object : View

Products Affected

netmaker

  • netmaker
CWE
CWE-347

Improper Verification of Cryptographic Signature