Information Disclosure in NeuVector Product Line
CVE-2026-25703

7.3HIGH

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-25703?

The NeuVector Manager version 5.4.9 is susceptible to a vulnerability that allows unauthorized information disclosure through its network/graph API. This occurs due to insufficient authentication controls, alongside cached data that may include sensitive information. When exploited, this vulnerability could potentially enable unauthorized access to critical information, posing risks to data security and privacy.

Affected Version(s)

NeuVector 0 <= 5.4.9

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.