PT-2026-23868 · Wireguard+1 · Wireguard+1

Artem Danilov

·

Published

2025-08-08

·

Updated

2026-03-25

·

CVE-2026-29194

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netmaker versions prior to 1.5.0
Description Netmaker, which utilizes WireGuard, has an issue where the Authorize middleware does not properly validate host JWT tokens. When host authentication is permitted (hostAllowed=true), a valid host token circumvents authorization checks without confirming the host's access rights to the requested resource. This allows entities with knowledge of object identifiers (node IDs, host IDs) to construct requests using a valid host token to access, modify, or delete resources belonging to other hosts. The following API endpoints are affected: node info retrieval, host deletion, MQTT signal transmission, fallback host updates, and failover operations. The vulnerable parameter is the host JWT token.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03334
CVE-2026-29194
GHSA-HMQR-WJMJ-376C
GO-2026-4655
SUSE-SU-2026:1042-1

Affected Products

Netmaker
Wireguard