Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78427— Admission Control Bypass via Hardcoded Sidecar Image Exemption

Quick assessment

Affected
go github.com/neuvector/neuvector
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NeuVector 准入 Webhook 在策略评估时会静默排除那些镜像路径匹配其中三个硬编码服务网格 sidecar 镜像的容器。由于镜像路径完全由工作负载作者控制,任何能够部署工作负载的用户都只需将其镜像路径命名为这三个 sidecar 镜像之一,即可绕过准入拒绝规则。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78427

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Admission Control Bypass via Hardcoded Sidecar Image Exemption
Source: CVE Program / CVE List V5
Vulnerability Description
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
在安全决策中依赖未经信任的输入
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
go github.com/neuvector/neuvector 0 ~ v5.6.1 -

II. Public POCs for CVE-2026-78427

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78427

登录查看更多情报信息。

Vendor Advisories for CVE-2026-78427 (1)

Vendor Pages for CVE-2026-78427 (1)

Same Patch Batch · go · 2026-09-17 · 4 CVEs total

CVE-2026-78428 8.0 HIGH Flaw in Nuevector can result in one user receiving another user's authenticated session wh
CVE-2026-78425 7.6 HIGH SAML Audience Confusion Allows Cross-SP Authentication
CVE-2026-78426 3.7 LOW Logout bypass via alternate JWT spelling

IV. Related Vulnerabilities

V. Comments for CVE-2026-78427

No comments yet


Leave a comment