← Back to search

CVE-2026-78424

8.8 HIGHpublic exploit available

Published 2026-09-28 · Updated 2026-09-29

AI risk analysis

Summary
This flaw allows any authenticated user with specific permissions to inject OS commands, leading to potential full compromise of the worker node.
Exploitability
Exploitation requires authentication and specific permissions, making it moderately difficult. Precondition is access to NeuVector's internal gRPC certificate key pair.
Blast radius
If exploited, it could result in the complete compromise of the worker node, impacting system integrity and availability.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to NeuVector 5.4.11 or later.
rceauth-bypassprivilege-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.