MEDIUM 5.3 NVD
CVE-2026-32599
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statement
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform boolean-based SQL injection. Version 1.5.0 fixes the issue.
References
- https://github.com/gravitl/netmaker/releases/tag/v1.5.0
- https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-15 via NVD.
vulnfeed aggregates 14340 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.