CVE-2026-38651
Published: Tue, 28 Apr 2026 16:16
Summary
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacke
Details
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
Are YOU affected by CVE-2026-38651?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-38651 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://github.com/gravitl/netmaker/commit/5309aa70d464ef565911369714d661a61481a79b
- https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass
- https://www.zyenra.com/blog/netmaker-jwt-verification-bypass
- https://www.zyenra.com/advisories/netmaker-jwt-verification-bypass/
- https://www.zyenra.com/blog/netmaker-jwt-verification-bypass
StackPatch runs this match against YOUR installed packages every hour
Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.