SAML Single Sign-On Vulnerability in NeuVector Affects Multiple Applications
CVE-2026-78425

7.6HIGH

Key Information:

Vendor

Go

Vendor
CVE Published:
17 September 2026

What is CVE-2026-78425?

A significant vulnerability exists within NeuVector's handling of SAML Single Sign-On assertions. Authorized users of external applications connected to the same corporate identity provider may inadvertently gain access to NeuVector through valid SAML assertions. This occurs because NeuVector's system accepts any assertion from the IdP without properly verifying the audience, specifically the absence of a NotInAudience check. Consequently, systems such as wikis, ticketing systems, and expense tools can pose a security risk, allowing unauthorized entry into NeuVector for users with legitimate accounts elsewhere.

Affected Version(s)

github.com/neuvector/neuvector 0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.