CVE-2026-78425

Source
https://cve.org/CVERecord?id=CVE-2026-78425
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78425.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78425
Aliases
  • GHSA-wgg5-24xq-px35
Published
2026-09-17T09:32:21Z
Modified
2026-09-20T11:30:37Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
SAML Audience Confusion Allows Cross-SP Authentication
Details

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the NotInAudience warning that reports the mismatch is never read.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-287"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78425.json"
}
References

Affected packages

Git / github.com/neuvector/neuvector

Affected ranges

Type
GIT
Repo
https://github.com/neuvector/neuvector
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "v5.6.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

controller/k8sapi/v1.*
controller/k8sapi/v1.0.0
v5.*
v5.0.0-b1
v5.0.0-b2
v5.0.0-preview.1
v5.0.0-preview.2
v5.0.0-preview.3
v5.1.0-rc1
v5.1.1
v5.1.1-b1
v5.2.0
v5.2.0-b1
v5.2.0-s1
v5.2.2-b1
v5.2.2-b2
v5.3.0-b1
v5.3.0-b2
v5.3.0-b3
v5.3.1-b1
v5.3.3-b1
v5.4.0-b1
v5.4.0-b1-bci
v5.4.0-b2
v5.4.0-b2-alpine
v5.4.0-b3
v5.4.1-alpha
v5.4.3-rc1
v5.4.3-rc2
v5.4.4
v5.4.4-rc1
v5.4.4-rc2
v5.4.5
v5.4.5-rc1
v5.4.5-rc2
v5.4.6-rc1
v5.4.7-rc1
v5.4.7-rc2
v5.4.8
v5.4.8-rc1
v5.4.8-rc2
v5.4.8-rc3
v5.4.9
v5.4.9-rc1
v5.4.9-rc2
v5.4.9-rc3
v5.5.0
v5.5.0-rc1
v5.5.0-rc2
v5.5.0-rc3
v5.5.0-rc4
v5.5.1-rc2
v5.5.1-rc3
v5.5.1-rc4
v5.6.0
v5.6.0-rc1
v5.6.0-rc3
v5.6.0-rc4
v5.6.1
v5.6.1-rc3
v5.6.1-rc4
v8040.*
v8040.1
vcilium.*
vcilium.1
veg.*
veg.1
vlogvul.*
vlogvul.1
vnsprune.*
vnsprune.1
voc415.*
voc415.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78425.json"