Missing Authorization Affecting github.com/forgekeep/nebula-mesh/internal/web package, versions <0.3.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMFORGEKEEPNEBULAMESHINTERNALWEB-17707770
  • published7 Jul 2026
  • disclosed26 Jun 2026
  • creditUnknown

Introduced: 26 Jun 2026

CVE-2026-49258  (opens in a new tab)
CWE-639  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade github.com/forgekeep/nebula-mesh/internal/web to version 0.3.6 or higher.

Overview

Affected versions of this package are vulnerable to Missing Authorization in the web UI handlers responsible for managing hosts and networks. An attacker can gain unauthorized access to sensitive information and perform destructive actions across resources owned by other operators by sending crafted requests to endpoints such as /ui/hosts/{id}/block, /ui/hosts/{id}, /ui/hosts, and /ui/networks. This is only exploitable if at least one non-admin operator exists in the deployment (such as when self-registration or OIDC is enabled, or an admin has created additional operators).

CVSS Base Scores

version 4.0
version 3.1