Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55513— nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens

Quick assessment

Affected
forgekeep nebula-mesh
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

nebula-mesh 是一个自托管的 Slack Nebula mesh VPN 控制平面组件。在 0.3.0 到 0.5.0 之前的版本中,nebula-mgmt 的 Web UI 主机创建流程忽略了全局安全设置中的 以及按网络配置的 覆盖值。虽然通过 API 创建主机和重新生成令牌的流程会正确使用已配置的 TTL 解析器,但 端点为新生成的代理入网令牌硬编码了 24 小时的有效性时长( )。因此,在那些有意缩短入网令牌有效期的部署环境中,任何能够登录 Web UI 创建主机的认证操作员,仍然可以签发一个有效期

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
forgekeep nebula-mesh >= 0.3.0, < 0.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Source: CVE Program / CVE List V5
Vulnerability Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network network_config.enrollment_token_ttl overrides. API host creation and token-regeneration paths use the configured TTL resolver, but POST /ui/hosts hardcodes now.Add(24 * time.Hour) for newly minted agent enrollment tokens. In deployments that intentionally reduce enrollment-token lifetime, any authenticated operator who can create a host through the Web UI can still mint a bearer enrollment token valid for about 24 hours. This issue has been patched in version 0.5.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
forgekeep nebula-mesh >= 0.3.0, < 0.5.0 -

II. Public POCs for CVE-2026-55513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55513

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55513 (1)

Vendor Advisories for CVE-2026-55513 (1)

Vendor Pages for CVE-2026-55513 (1)

Same Patch Batch · forgekeep · 2026-09-04 · 7 CVEs total

CVE-2026-61699 8.1 HIGH nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-63464 7.7 HIGH Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva
CVE-2026-53603 7.1 HIGH nebula-mesh: Operator session tokens stored in plaintext in the database
CVE-2026-53604 7.1 HIGH nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVE-2026-53602 6.9 MEDIUM nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid
CVE-2026-55512 5.3 MEDIUM nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri

IV. Related Vulnerabilities

V. Comments for CVE-2026-55513

No comments yet


Leave a comment