Vulnerability Description
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/tale/headplane/releases/tag/v0.6.3
- https://github.com/tale/headplane/releases/tag/v0.7.0-beta.3
- https://github.com/tale/headplane/security/advisories/GHSA-vgj6-hcf2-fqf6
FAQ
What is CVE-2026-46484?
CVE-2026-46484 is a vulnerability with a CVSS score of 8.1 (HIGH). Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by ...
How severe is CVE-2026-46484?
CVE-2026-46484 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46484?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.