Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53603— nebula-mesh: Operator session tokens stored in plaintext in the database

Quick assessment

Affected
forgekeep nebula-mesh
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

nebula-mesh 是一个自托管的 Slack Nebula mesh VPN 控制平面。在 0.3.8 版本之前,操作员会话令牌以明文形式存储在 表中( 列为主键)。会话令牌是一个 32 字节的随机十六进制值,直接通过 Cookie 发送,有效期为 24 小时。任何能够读取数据库的人(通过备份、快照、文件复制或 SQL 级别的信息泄露)都能获取所有活动的会话令牌,并直接劫持操作员会话,无需进一步的身份验证。该问题已在 0.3.8 版本中修复。

CVSS 7.1 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
forgekeep nebula-mesh < 0.3.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53603

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nebula-mesh: Operator session tokens stored in plaintext in the database
Source: CVE Program / CVE List V5
Vulnerability Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
forgekeep nebula-mesh < 0.3.8 -

II. Public POCs for CVE-2026-53603

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53603

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53603 (1)

Vendor Advisories for CVE-2026-53603 (1)

Vendor Pages for CVE-2026-53603 (1)

Same Patch Batch · forgekeep · 2026-09-04 · 7 CVEs total

CVE-2026-61699 8.1 HIGH nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-63464 7.7 HIGH Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva
CVE-2026-53604 7.1 HIGH nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVE-2026-53602 6.9 MEDIUM nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid
CVE-2026-55513 5.4 MEDIUM nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou
CVE-2026-55512 5.3 MEDIUM nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri

IV. Related Vulnerabilities

V. Comments for CVE-2026-53603

No comments yet


Leave a comment