CVEFinder.io

CVE-2026-38651

⚠️ high
🔍 Scan for this CVE
Summary

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information

CVSS Score
8.2
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-04-28
First Seen: 2026-05-19
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 79.7% of all 326,604 vulnerabilities in our database.

#66,460
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Apr 28, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-05-18
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 4

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-29771 🔶 medium 6.5 0.0 Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ... 2026-03-07
CVE-2023-32077 ⚠️ high 7.5 86.6 Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in N... 2023-08-24
CVE-2023-32078 ⚠️ high 7.5 0.2 Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions p... 2023-08-24
CVE-2023-32079 ⚠️ high 8.8 1.0 Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6... 2023-08-24
CVE-2022-36110 ⚠️ high 8.8 0.3 Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged... 2022-09-09
CVE-2022-0664 ⛔ critical 9.8 0.3 Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1. 2022-02-18
These CVEs affect the same products