CVE-2026-29195

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does not include an equivalent check for the super-admin role. This issue has been patched in version 1.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*

History

12 Mar 2026, 13:57

Type Values Removed Values Added
Summary
  • (es) Netmaker crea redes con WireGuard. Antes de la versión 1.5.0, el gestor de actualización de usuarios (PUT /api/users/{username}) carece de validación para evitar que un usuario con rol de administrador asigne el rol de superadministrador durante las actualizaciones de cuenta. Si bien el código bloquea correctamente que un administrador asigne el rol de administrador a otro usuario, no incluye una verificación equivalente para el rol de superadministrador. Este problema ha sido parcheado en la versión 1.5.0.
CPE cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Gravitl netmaker
Gravitl
References () https://github.com/gravitl/netmaker/releases/tag/v1.5.0 - () https://github.com/gravitl/netmaker/releases/tag/v1.5.0 - Product, Release Notes
References () https://github.com/gravitl/netmaker/security/advisories/GHSA-ch3w-9456-38v3 - () https://github.com/gravitl/netmaker/security/advisories/GHSA-ch3w-9456-38v3 - Vendor Advisory

07 Mar 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 17:15

Updated : 2026-03-12 13:57


NVD link : CVE-2026-29195

Mitre link : CVE-2026-29195

CVE.ORG link : CVE-2026-29195


JSON object : View

Products Affected

gravitl

  • netmaker
CWE
CWE-863

Incorrect Authorization