Security Flaw: Privilege Escalation in Nebula API

Options
henriquev
henriquev Posts: 21 image  Freshman Member
First Comment Friend Collector First Anniversary

Hello,

We have identified that a user with "read-only" permissions can perform write actions, such as creating a new site within our organization, by using an API key (created by the user in his account). This same action is correctly blocked in the user interface (UI).

This loophole allows for improper privilege escalation and violates the principle of least privilege, creating a security risk for our organization. I have not yet tested with other API calls like register devices and moving devices between sites.

Could you please inform us if there are any controls to mitigate this? Are there plans (a roadmap) to align API permissions with UI permissions, thereby restricting read-only users to GET calls?

Best Answers

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @henriquev

    Thanks for reporting this issue. This issue has been addressed and will be fixed asap. Will keep you posted once fixed.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Update:

    We have fixed this issue on 2026/02/10.

    Zyxel Melen


All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @henriquev

    Thanks for reporting this issue. This issue has been addressed and will be fixed asap. Will keep you posted once fixed.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Update:

    We have fixed this issue on 2026/02/10.

    Zyxel Melen


Nebula Tips & Tricks