CVE-2026-25703

Summary

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

Affected Software

VendorProductVersion RangeStatus
SUSENeuVector0 <= 5.4.9affected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function
  • CWE-524: CWE-524 Use of cache containing sensitive information
  • CWE-202: CWE-202 Exposure of sensitive information through data queries

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References