CVE-2026-53603High· 7.1▾ Twilightnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
7.1 → —
— → 7.1
7.1 → —
— → 7.1
7.1 → —
— → 7.1
7.1 → —
— → 7.1
7.1 → —
— → 7.1
7.1 → —
— → 7.1
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/forgekeep/nebula-mesh <= 0.3.7Patched in:
github.com/forgekeep/nebula-mesh 0.3.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53604High· 7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-63464High· 7.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-55512Medium· 5.3nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-55513Medium· 5.4nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-61699High· 8.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
CVE-2026-63406Medium· 5.9AnyCable is a realtime server for reliable two-way communication that supports any backend