PT-2026-82222 · Netmaker · Netmaker

·

CVE-2026-81034

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netmaker (affected versions not specified)
Description Netmaker disables certificate verification when connecting to the configured mail server. In the file pro/email/smtp.go, the sender assigns a TLS configuration where the skip-verify field is unconditionally set to true. Because no configuration value governs this setting and no code path restores verification, the client accepts any certificate presented by the mail server, including those from an interposing party. This allows an attacker positioned between the server and its mail relay to perform a man-in-the-middle attack to read messages in transit, such as password-reset messages containing single-use tokens and user invitations containing enrolment links, potentially allowing the attacker to use captured reset tokens.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81034

Affected Products

Netmaker