CVE-2026-47724: nebula-mesh API Authorization Bypass Enables Cross-Tenant Takeover (CVSS 9.9)
ID: ac4f69a2-d9ad-591d-a3a9-c6fea6f24312
STIX ID: report--ac4f69a2-d9ad-591d-a3a9-c6fea6f24312
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-47724 — nebula-mesh critical authorization bypass:** A flaw in nebula-mesh (< v0.3.4) allows any valid operator API key to bypass per-CA ownership checks on the /api/v1/* endpoints, enabling cross-tenant read/modify access to hosts, networks, firewall rules, and mobile bundles; the issue is fixed in v0.3.4 and operators are advised to upgrade immediately, rotate operator API keys, and apply interim network restrictions if they cannot upgrade right away.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
