CVE-2026-29196
Netmaker <1.5.0 - Info Disclosure
Title source: llmDescription
Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/extclients/{network} or GET /api/nodes/{network}. While the Netmaker UI restricts visibility, the API endpoints return full records, including private keys, without filtering based on the requesting user's ownership. This issue has been patched in version 1.5.0.
Scores
EPSS
0.0004
EPSS Percentile
12.2%
Classification
CWE
CWE-863
Status
draft
Affected Products (1)
gravitl/netmaker
< 1.5.0Go
Timeline
Published
Mar 07, 2026
Tracked Since
Mar 08, 2026