VYPR
Vendor

Neuvector

Products
2
CVEs
17
Across products
17
Status
Private

Products

2

Recent CVEs

17
  • CVE-2019-19747CriDec 20, 2019
    risk 0.64cvss 9.8epss 0.01

    NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that…

  • CVE-2025-54469CriOct 30, 2025
    risk 0.57cvss 9.9epss 0.00

    A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a command to be executed via popen, without first sanitising their values. The entry process of the enforcer container is the monitor …

  • CVE-2025-8077CriSep 17, 2025
    risk 0.57cvss 9.8epss 0.01

    A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could…

  • CVE-2023-32188CriOct 16, 2024
    risk 0.54cvss —epss 0.00

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

  • CVE-2026-78424HigSep 28, 2026
    risk 0.50cvss 8.8epss —

    Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container,…

  • CVE-2026-78428HigSep 17, 2026
    risk 0.50cvss —epss 0.00

    For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

  • CVE-2025-66001HigJan 8, 2026
    risk 0.50cvss 8.8epss 0.00

    NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

  • CVE-2026-78425HigSep 17, 2026
    risk 0.49cvss —epss 0.00

    Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If…

  • CVE-2025-54470HigOct 30, 2025
    risk 0.49cvss 8.6epss 0.00

    This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVector does not enforce TLS certificate…

  • CVE-2026-25703HigAug 5, 2026
    risk 0.47cvss 7.3epss 0.01

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

  • CVE-2025-46808MedSep 9, 2026
    risk 0.37cvss 6.8epss 0.00

    An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

  • CVE-2023-22644MedSep 20, 2023
    risk 0.36cvss 5.5epss 0.00

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

  • CVE-2025-54471MedOct 30, 2025
    risk 0.35cvss 6.5epss 0.00

    NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.

  • CVE-2026-78427MedSep 17, 2026
    risk 0.34cvss —epss 0.00

    The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can…

  • CVE-2025-54467MedSep 17, 2025
    risk 0.27cvss 5.3epss 0.00

    When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.

  • CVE-2025-53884MedSep 17, 2025
    risk 0.27cvss 5.3epss 0.00

    NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).

  • CVE-2026-78426LowSep 17, 2026
    risk 0.13cvss —epss 0.00

    The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature…