OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-78424

HIGH · CVSS 8.8 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

NeuVector is vulnerable due to improper parameter handling, allowing authenticated users with specific permissions or access to internal gRPC certificate keys to inject OS commands into the privileged enforcer container. This vulnerability can lead to a complete compromise of the worker node, posing a significant risk to system integrity. Organizations using affected versions of NeuVector should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78424
Severity
HIGH
CVSS
8.8
EPSS
0.20%

Original NVD Description

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.