CVE-2026-47722

Juev · nebula-mesh

The nebula-mesh self-hosted control plane is vulnerable to code injection, which may allow an authenticated attacker to execute arbitrary code within the mesh environment.

Executive summary

A code injection vulnerability in the nebula-mesh control plane, rated as High severity, allows authenticated users to execute arbitrary code, threatening the integrity of the virtual private network.

Vulnerability

This vulnerability is identified as CWE-94 (Improper Control of Generation of Code). It allows a low-privileged authenticated attacker to inject and execute code on the control plane, which manages the Nebula mesh network.

Business impact

Exploitation of this flaw could result in complete compromise of the control plane, allowing an attacker to manipulate network configurations, intercept traffic, or disrupt the virtual private network entirely. With a CVSS score of 8.7, this vulnerability poses a severe risk to the network infrastructure and organizational data security.

Remediation

Immediate Action: Update the nebula-mesh control plane to version 0.3.2 or later immediately.

Proactive Monitoring: Review control plane access logs for anomalous command execution or unauthorized attempts to modify network configurations.

Compensating Controls: Restrict access to the nebula-mesh management interface to a trusted and isolated network segment, effectively mitigating the risk of exploitation by unauthorized or compromised accounts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of the nebula-mesh control plane within the network infrastructure, this vulnerability requires immediate attention. Security teams must ensure that all instances are updated to the patched version to prevent potential remote code execution and network takeover.