{"id":"GO-2026-5816","summary":"Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh","details":"Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh","aliases":["CVE-2026-49258","GHSA-c6v2-3ffm-vcmc"],"modified":"2026-07-07T16:00:21.316246464Z","published":"2026-07-07T15:26:32Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5816","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/juev/nebula-mesh/security/advisories/GHSA-c6v2-3ffm-vcmc"}],"affected":[{"package":{"name":"github.com/juev/nebula-mesh","ecosystem":"Go","purl":"pkg:golang/github.com/juev/nebula-mesh"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5816.json"}}],"schema_version":"1.7.5"}