CVE-2026-29196 describes a critical information disclosure vulnerability in Netmaker versions prior to 1.5.0, allowing users with the platform-user role to retrieve WireGuard private keys for all network configurations. This flaw stems from API endpoints (GET /api/extclients/{network} and GET /api/nodes/{network}) returning full records without proper filtering, despite UI restrictions. With a CVSS score of 8.7 (HIGH), this vulnerability presents a significant risk of unauthorized access to sensitive network credentials due to its low attack complexity and lack of user interaction required. While there is currently no evidence of active exploitation, public exploit code, or significant community discussion, the potential for compromise remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.