CVE-2026-38651 | Netmaker up to 1.4.x logic/jwts.go VerifyHostToken information disclosure (EUVD-2026-26062)
A vulnerability identified as problematic has been detected in Netmaker up to 1.4.x. Impacted is the function VerifyHostToken of the file logic/jwts.go. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-38651. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.