PT-2026-82222 · Netmaker · Netmaker
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Netmaker (affected versions not specified)
Description
Netmaker disables certificate verification when connecting to the configured mail server. In the file
pro/email/smtp.go, the sender assigns a TLS configuration where the skip-verify field is unconditionally set to true. Because no configuration value governs this setting and no code path restores verification, the client accepts any certificate presented by the mail server, including those from an interposing party. This allows an attacker positioned between the server and its mail relay to perform a man-in-the-middle attack to read messages in transit, such as password-reset messages containing single-use tokens and user invitations containing enrolment links, potentially allowing the attacker to use captured reset tokens.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netmaker