← Back to overview

CVE-2026-61699 affects nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN, in versions prior to 0.7.1. The vulnerability stems from a flawed revocation mechanism where blocklist entries are never propagated to peers' config.yml files. This allows a blocked or offboarded host to retain full overlay network reachability for up to 30 days (agent) or 365 days (mobile). An attacker who has exfiltrated a host's private key and certificate can bypass the revocation by running the stock Nebula client and ignoring 403/410 HTTP responses from the control plane. The operator-facing UI falsely shows the host as blocked, creating a misleading security posture. The vulnerability enables persistent unauthorized access to internal mesh services even after explicit revocation. A patch has been issued in version 0.7.1 of nebula-mesh.

Affected products

  • Slack Nebula mesh VPN
  • nebula-mesh

Related CVE's

  • CVE-2026-61699

Categories

  • Identity & Access
  • Network Infrastructure