top of page
perceptive_background_267k.jpg

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive i…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 11:01:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access, Data Breach & Exfiltration, Security Tools

CVE-2026-25703 affects NeuVector versions through 5.4.9, exposing a vulnerability in the manager /network/graph API endpoint. The flaw stems from missing authentication controls combined with cached data that may contain sensitive information. An unauthenticated attacker could potentially access sensitive network graph data without any credentials. The vulnerability was reported via SUSE Bugzilla and has a corresponding GitHub Security Advisory (GHSA-hx45-873x-74qv). NeuVector is a container security platform widely used in enterprise Kubernetes environments, making this exposure particularly significant. The lack of authentication on an API endpoint that returns cached sensitive data represents a serious information disclosure risk. Users are advised to update beyond version 5.4.9 once a patch is available.

Technical details

Mitigation steps:

Affected products:

NeuVector

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page