CVE-2026-78427

Source
https://cve.org/CVERecord?id=CVE-2026-78427
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78427.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78427
Aliases
  • GHSA-78r4-3wfq-r2xm
Published
2026-09-17T09:33:26Z
Modified
2026-09-20T11:30:28Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Admission Control Bypass via Hardcoded Sidecar Image Exemption
Details

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-807"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78427.json"
}
References

Affected packages

Git / github.com/neuvector/neuvector

Affected ranges

Type
GIT
Repo
https://github.com/neuvector/neuvector
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "v5.6.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

controller/k8sapi/v1.*
controller/k8sapi/v1.0.0
v5.*
v5.0.0-b1
v5.0.0-b2
v5.0.0-preview.1
v5.0.0-preview.2
v5.0.0-preview.3
v5.1.0-rc1
v5.1.1
v5.1.1-b1
v5.2.0
v5.2.0-b1
v5.2.0-s1
v5.2.2-b1
v5.2.2-b2
v5.3.0-b1
v5.3.0-b2
v5.3.0-b3
v5.3.1-b1
v5.3.3-b1
v5.4.0-b1
v5.4.0-b1-bci
v5.4.0-b2
v5.4.0-b2-alpine
v5.4.0-b3
v5.4.1-alpha
v5.4.3-rc1
v5.4.3-rc2
v5.4.4
v5.4.4-rc1
v5.4.4-rc2
v5.4.5
v5.4.5-rc1
v5.4.5-rc2
v5.4.6-rc1
v5.4.7-rc1
v5.4.7-rc2
v5.4.8
v5.4.8-rc1
v5.4.8-rc2
v5.4.8-rc3
v5.4.9
v5.4.9-rc1
v5.4.9-rc2
v5.4.9-rc3
v5.5.0
v5.5.0-rc1
v5.5.0-rc2
v5.5.0-rc3
v5.5.0-rc4
v5.5.1-rc2
v5.5.1-rc3
v5.5.1-rc4
v5.6.0
v5.6.0-rc1
v5.6.0-rc3
v5.6.0-rc4
v5.6.1
v5.6.1-rc3
v5.6.1-rc4
v8040.*
v8040.1
vcilium.*
vcilium.1
veg.*
veg.1
vlogvul.*
vlogvul.1
vnsprune.*
vnsprune.1
voc415.*
voc415.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78427.json"