CVE-2026-38651
⚠️ highSummary
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information
CVSS Score
8.2
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-04-28
First Seen: 2026-05-19
📊 Relative Risk Intelligence
This CVE is High Risk - more severe than 79.7% of all 326,604 vulnerabilities in our database.
#66,460
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Apr 28, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by
CISA
Last Modified
2026-05-18
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE IDs (Weakness Types)