{"id":"CVE-2026-78424","published":"2026-09-28T12:17:40.897","lastModified":"2026-09-29T21:32:59.833","description":"Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-vr77-8vmq-qfmj","tags":[]}],"exploitRefs":[{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-vr77-8vmq-qfmj","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows any authenticated user with specific permissions to inject OS commands, leading to potential full compromise of the worker node.","exploitability":"Exploitation requires authentication and specific permissions, making it moderately difficult. Precondition is access to NeuVector's internal gRPC certificate key pair.","blast_radius":"If exploited, it could result in the complete compromise of the worker node, impacting system integrity and availability.","remediation":"Upgrade to NeuVector 5.4.11 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","privilege-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:07:07.094Z"}}