PT-2026-23871 · Wireguard+1 · Wireguard+1

·

CVE-2026-29196

·

Published

2025-08-08

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netmaker versions prior to 1.5.0
Description Netmaker, a networking tool utilizing WireGuard, contains an issue where a user with the platform-user role can access WireGuard private keys for all configurations within a network. This occurs through the use of specific API endpoints without proper filtering based on user ownership. The affected API Endpoints are /api/extclients/{network} and /api/nodes/{network}. The issue allows unauthorized retrieval of sensitive data, including WireGuard private keys, despite UI restrictions intended to limit visibility. The variable {network} represents the network identifier.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03336
CVE-2026-29196
GHSA-4HGG-C4RR-6H7F
GO-2026-4651
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1042-1

Affected Products

Netmaker
Wireguard