CVE-2026-61699
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every peer under its CA (and internal services on the mesh) for up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.key+host.crt can run stock slackhq/nebula directly, ignore the agent's 403/410 poll responses, and stay connected after the operator revokes the host. Operator-visible state (UI shows blocked, audit log records it) is misleading. This issue has been patched in version 0.7.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-299, CWE-672
- Published
- 2026-09-04
- Last modified
- 2026-09-08
Affected products
- forgekeep nebula-mesh
Weakness type
Related vulnerabilities
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-6899 — Improper Check for Certificate Revocation in S2OPC
- CVE-2026-4428 — CRL Distribution Point Scope Check Logic Error in AWS-LC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-36057 — IBM Cognos Analytics Mobile (iOS) authentication bypass
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked