PT-2026-94203 · Neuvector · Neuvector

CVE-2026-78427

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NeuVector (affected versions not specified)
Description The admission webhook silently excludes containers from policy evaluation if their image path matches one of three hardcoded service mesh sidecar images. Because the image path is controlled by the workload author, a user with deployment permissions can bypass admission deny rules by naming their image path to match one of these sidecar images.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78427
GHSA-78R4-3WFQ-R2XM

Affected Products

Neuvector