Admission Webhook Bypass in NeuVector Service Mesh by NeuVector
CVE-2026-78427

4.3MEDIUM

Key Information:

Vendor

Go

Vendor
CVE Published:
17 September 2026

What is CVE-2026-78427?

The NeuVector admission webhook is vulnerable due to improper handling of specific container image paths related to service mesh sidecar images. This flaw permits users to deploy workloads with image paths that match these hardcoded values, allowing them to bypass security policies that would ordinarily trigger a denial for non-compliant images. Consequently, this vulnerability can lead to unauthorized container deployments, exposing the system to various security risks.

Affected Version(s)

github.com/neuvector/neuvector 0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.