Security Advisories and CVEs

NeuVector is committed to informing the community about security issues. The following table lists published security advisories and CVEs (Common Vulnerabilities and Exposures) for resolved issues.

CVE List

ID Description Date Resolution

CVE-2026-78424

Fixed a security vulnerability where improper parameter handling allowed any authenticated users access to inject OS commands in the privileged enforcer container, which could lead to the complete compromise of the worker node.

15 September 2026

NeuVector v5.6.2

CVE-2026-78425

Fixed a security vulnerability regarding improper authentication where starting from version v5.6.2, users can configure the “Audience URI” in the Settings → SAML Settings page. After the “Audience URI” is configured, it is used and checked during SAML SSO so that assertion for other applications won’t be accepted by SUSE Security.

15 September 2026

NeuVector v5.6.2

CVE-2026-78426

Fixed a security vulnerability where the SUSE Security JWT verifier accepted non-canonical Base64URL encodings of the same RSA signature, so an attacker holding a valid token could continue using a token that is expired or logged out by using its equivalent spelling. Starting from version v5.6.2, the SUSE Security JWT verifier requires the JWT token to be a unique compact serialization.

15 September 2026

NeuVector v5.6.2

CVE-2026-78427

Fixed a security vulnerability where the SUSE Security admission webhook silently excluded containers from policy evaluation when their image path matched one of three hard-coded service mesh sidecar images. This could lead malicious users to deploy workloads by evading admission deny rules by naming their image path after one of these sidecar images. Starting from version v5.6.2, the automatic sidecar exemptions are removed entirely.

15 September 2026

NeuVector v5.6.2

CVE-2026-78428

Fixed a security vulnerability for users that authenticated through SAML or OpenID Connect (OIDC). This vulnerability would result in one user receiving another user’s authenticated session when multiple SSO login attempts occurred concurrently.

15 September 2026

NeuVector v5.6.2

Questions and Support