{"id":"CVE-2026-53603","title":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN","summary":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-312","CWE-522"],"vendor":"forgekeep","product":"nebula-mesh","affected":["nebula-mesh < 0.3.8"],"patched":["github.com/forgekeep/nebula-mesh 0.3.8"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T21:05:26.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53603","references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e","label":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8","label":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-q4vm-pq3q-8wgq"}],"tags":["nvd","cve.org","ghsa","go"],"epss":0.00204,"epssPercentile":0.10666,"aliases":["GHSA-q4vm-pq3q-8wgq"],"ecosystem":"go","ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T17:48:58.655747Z"},"cvssSource":"cna","ingestedAt":"2026-07-14T20:39:11.207Z","slug":"CVE-2026-53603","body":"## Overview\n\nnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-53603)\n\nAffected packages:\n\n- `github.com/forgekeep/nebula-mesh <= 0.3.7`\n\nPatched in:\n\n- `github.com/forgekeep/nebula-mesh 0.3.8`\n\nSource: https://github.com/advisories/GHSA-q4vm-pq3q-8wgq","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":8189,"id":"CVE-2026-53603","ts":1788919973132,"field":"cvss","old":null,"new":"7.1"},{"seq":7998,"id":"CVE-2026-53603","ts":1788919275547,"field":"cvss","old":"7.1","new":null},{"seq":7807,"id":"CVE-2026-53603","ts":1788916333740,"field":"cvss","old":null,"new":"7.1"},{"seq":7616,"id":"CVE-2026-53603","ts":1788915291784,"field":"cvss","old":"7.1","new":null},{"seq":7425,"id":"CVE-2026-53603","ts":1788912694979,"field":"cvss","old":null,"new":"7.1"},{"seq":7234,"id":"CVE-2026-53603","ts":1788911324074,"field":"cvss","old":"7.1","new":null},{"seq":7041,"id":"CVE-2026-53603","ts":1788909061072,"field":"cvss","old":null,"new":"7.1"},{"seq":6853,"id":"CVE-2026-53603","ts":1788907385659,"field":"cvss","old":"7.1","new":null},{"seq":6655,"id":"CVE-2026-53603","ts":1788905428437,"field":"cvss","old":null,"new":"7.1"},{"seq":6473,"id":"CVE-2026-53603","ts":1788903454757,"field":"cvss","old":"7.1","new":null},{"seq":6268,"id":"CVE-2026-53603","ts":1788901797355,"field":"cvss","old":null,"new":"7.1"},{"seq":6098,"id":"CVE-2026-53603","ts":1788899558104,"field":"cvss","old":"7.1","new":null},{"seq":5909,"id":"CVE-2026-53603","ts":1788898149167,"field":"cvss","old":null,"new":"7.1"},{"seq":5798,"id":"CVE-2026-53603","ts":1788895705311,"field":"cvss","old":"7.1","new":null},{"seq":5670,"id":"CVE-2026-53603","ts":1788894522501,"field":"cvss","old":null,"new":"7.1"},{"seq":5628,"id":"CVE-2026-53603","ts":1788891865953,"field":"cvss","old":"7.1","new":null},{"seq":5599,"id":"CVE-2026-53603","ts":1788890891145,"field":"cvss","old":null,"new":"7.1"}]}