{"id":"CVE-2026-25703","published":"2026-08-05T10:17:27.300","lastModified":"2026-08-05T14:17:05.593","description":"NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-202","CWE-306","CWE-524"],"vendors":[],"products":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-25703","tags":[]},{"url":"https://github.com/neuvector/manager/security/advisories/GHSA-hx45-873x-74qv","tags":[]}],"exploitRefs":[{"url":"https://github.com/neuvector/manager/security/advisories/GHSA-hx45-873x-74qv","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows unauthorized access to sensitive information via the /network/graph API due to missing authentication, posing a significant security risk.","exploitability":"Exploitation is relatively easy given that no authentication is required, and cached data containing sensitive information can be accessed.","blast_radius":"If exploited, this could lead to data breaches affecting multiple users or systems with sensitive network information being exposed.","remediation":"Implement proper authentication mechanisms for the /network/graph API endpoint in NeuVector versions prior to 5.4.10.","tags":["auth-bypass","api","info-leak","security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:00:51.147Z"}}