CVE-2026-25703
7.3 HIGHpublic exploit availablePublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows unauthorized access to sensitive information via the /network/graph API due to missing authentication, posing a significant security risk.
- Exploitability
- Exploitation is relatively easy given that no authentication is required, and cached data containing sensitive information can be accessed.
- Blast radius
- If exploited, this could lead to data breaches affecting multiple users or systems with sensitive network information being exposed.
- Prioritized remediation
- Implement proper authentication mechanisms for the /network/graph API endpoint in NeuVector versions prior to 5.4.10.
auth-bypassapiinfo-leaksecurity
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-202, CWE-306, CWE-524
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.