CVE-2026-53603EPSS p26.6%
CVE-2026-53603CVE-2026-53603
Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.
Scoring
| EPSS | 0.35% probability of exploitation · percentile 26.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |