CVE-2026-29196

Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/extclients/{network} or GET /api/nodes/{network}. While the Netmaker UI restricts visibility, the API endpoints return full records, including private keys, without filtering based on the requesting user's ownership. This issue has been patched in version 1.5.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*

History

12 Mar 2026, 13:44

Type Values Removed Values Added
Summary
  • (es) Netmaker crea redes con WireGuard. Antes de la versión 1.5.0, un usuario asignado al rol de usuario 'platform-user' puede recuperar las claves privadas de WireGuard de todas las configuraciones de WireGuard en una red al llamar a GET /api/extclients/{network} o GET /api/nodes/{network}. Si bien la interfaz de usuario de Netmaker restringe la visibilidad, los endpoints de la API devuelven registros completos, incluyendo las claves privadas, sin filtrar basándose en la propiedad del usuario solicitante. Este problema ha sido parcheado en la versión 1.5.0.
First Time Gravitl netmaker
Gravitl
CPE cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () https://github.com/gravitl/netmaker/releases/tag/v1.5.0 - () https://github.com/gravitl/netmaker/releases/tag/v1.5.0 - Product, Release Notes
References () https://github.com/gravitl/netmaker/security/advisories/GHSA-4hgg-c4rr-6h7f - () https://github.com/gravitl/netmaker/security/advisories/GHSA-4hgg-c4rr-6h7f - Vendor Advisory

07 Mar 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 17:15

Updated : 2026-03-12 13:44


NVD link : CVE-2026-29196

Mitre link : CVE-2026-29196

CVE.ORG link : CVE-2026-29196


JSON object : View

Products Affected

gravitl

  • netmaker
CWE
CWE-863

Incorrect Authorization