PT-2026-94201 · Neuvector · Neuvector

CVE-2026-78425

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NeuVector (affected versions not specified)
Description Users authorized for external applications sharing the same corporate identity provider (IdP), such as a wiki or ticketing system, can gain unauthorized access to the system via SAML SSO. This occurs because the system fails to process the NotInAudience warning, which is the only element distinguishing a SAML assertion intended for another application from one intended for NeuVector.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78425
GHSA-WGG5-24XQ-PX35

Affected Products

Neuvector