← Back to search

CVE-2026-25703

7.3 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows unauthorized access to sensitive information via the /network/graph API due to missing authentication, posing a significant security risk.
Exploitability
Exploitation is relatively easy given that no authentication is required, and cached data containing sensitive information can be accessed.
Blast radius
If exploited, this could lead to data breaches affecting multiple users or systems with sensitive network information being exposed.
Prioritized remediation
Implement proper authentication mechanisms for the /network/graph API endpoint in NeuVector versions prior to 5.4.10.
auth-bypassapiinfo-leaksecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-202, CWE-306, CWE-524

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.