Security Advisory

CVE-2026-29195

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-07 16:14:06
Last updated 2026-03-09 18:25:40
Assigner GitHub_M
CVSS score 6.9
State PUBLISHED

Description

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does not include an equivalent check for the super-admin role. This issue has been patched in version 1.5.0.