CVE-2026-25703
Received Received - Intake

NeuVector Manager Network Graph Information Leak

Vulnerability report for CVE-2026-25703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: SUSE

Description

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph APIΒ due to missing authentication and cached data containing sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
neuvector neuvector to 5.4.9 (inc)
neuvector manager to 5.4.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-202 When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NeuVector through version 5.4.9 has a vulnerability where unauthenticated users can access sensitive cached or static data through certain API endpoints. This occurs because session token verification is missing for these endpoints, allowing unauthorized access to system information like host details, workload names, compliance data, and network configurations.

Detection Guidance

Check for unauthorized access to NeuVector API endpoints like /network/graph, /audit2, or /risk/complianceNIST. Monitor logs for requests to these paths without valid session tokens. Use network scanning tools to detect unusual traffic to these endpoints.

Impact Analysis

An attacker could exploit this to retrieve sensitive environment data without authentication. This includes system details, network structures, and compliance information, potentially leading to further attacks or data breaches.

Compliance Impact

This vulnerability could expose sensitive data, potentially violating GDPR or HIPAA requirements for data protection and confidentiality. Unauthorized access to compliance-related data may lead to regulatory penalties or loss of trust.

Mitigation Strategies

Upgrade NeuVector to version 5.5.0 or later to add session token verification. Review and restrict access to hidden API endpoints in the UI. Rotate any GitHub tokens used in Remote Repository Configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart