FlawAtlas
Search the atlas
CVE-2026-29195 Moderate

Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker

Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker

Exploit probability 0.2%
Published March 11, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

64 explicit affected versions

Go github.com/gravitl/netmaker
Go github.com/gravitl/netmaker

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-ch3w-9456-38v3

The user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does not include an equivalent check for the super-admin role. > Credits > Artem Danilov (Positive Technologies)

View original source
Open Source Vulnerabilities GO-2026-4654

Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker

View original source
Open Source Vulnerabilities CVE-2026-29195

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does not include an equivalent check for the super-admin role. This issue has been patched in version 1.5.0.

View original source

05 / REFERENCES

Further evidence