CVE-2026-38651

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
Configurations

Configuration 1 (hide)

cpe:2.3:a:netmaker:netmaker:*:*:*:*:*:*:*:*

History

18 May 2026, 16:41

Type Values Removed Values Added
References () https://github.com/gravitl/netmaker/commit/5309aa70d464ef565911369714d661a61481a79b - () https://github.com/gravitl/netmaker/commit/5309aa70d464ef565911369714d661a61481a79b - Patch
References () https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass - () https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass - Exploit, Third Party Advisory
References () https://www.zyenra.com/blog/netmaker-jwt-verification-bypass - () https://www.zyenra.com/blog/netmaker-jwt-verification-bypass - Exploit, Third Party Advisory
References () https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/ - () https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/ - Exploit, Third Party Advisory
First Time Netmaker netmaker
Netmaker
CPE cpe:2.3:a:netmaker:netmaker:*:*:*:*:*:*:*:*

28 Apr 2026, 19:37

Type Values Removed Values Added
References
  • () https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/ -
References () https://www.zyenra.com/blog/netmaker-jwt-verification-bypass - () https://www.zyenra.com/blog/netmaker-jwt-verification-bypass -
CWE CWE-347
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2

28 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 16:16

Updated : 2026-05-18 16:41


NVD link : CVE-2026-38651

Mitre link : CVE-2026-38651

CVE.ORG link : CVE-2026-38651


JSON object : View

Products Affected

netmaker

  • netmaker
CWE
CWE-347

Improper Verification of Cryptographic Signature