CVE-2026-78424

Source
https://cve.org/CVERecord?id=CVE-2026-78424
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78424.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78424
Aliases
  • GHSA-vr77-8vmq-qfmj
Published
2026-09-28T11:44:05Z
Modified
2026-10-01T03:31:05Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
Details

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-78"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78424.json"
}
References

Affected packages

Git / github.com/neuvector/neuvector

Affected ranges

Type
GIT
Repo
https://github.com/neuvector/neuvector
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.4"
        },
        {
            "fixed":  "5.4.11"
        },
        {
            "introduced":  "5.5"
        },
        {
            "fixed":  "5.5.4"
        },
        {
            "introduced":  "5.6"
        },
        {
            "fixed":  "5.6.2"
        }
    ],
    "source":  "DESCRIPTION"
}

Affected versions

v5.*
v5.5.0
v5.5.0-rc3
v5.5.0-rc4
v5.5.1
v5.5.1-rc2
v5.5.1-rc3
v5.5.1-rc4
v5.5.1-rc5
v5.5.2
v5.5.2-rc2
v5.5.2-rc3
v5.5.3
v5.5.3-rc1
v5.5.4-rc1
v5.6.0
v5.6.0-rc4
v5.6.1
v5.6.1-rc3
v5.6.1-rc4
v5.6.2-rc2
v5.6.2-rc3
v5.6.2-rc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78424.json"