NeuVector 5.6.1 SAML SSO Assertion Auth Bypass via IdP
CVE-2026-78425 Published on September 17, 2026

SAML Audience Confusion Allows Cross-SP Authentication
Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the `NotInAudience` warning that reports the mismatch is never read.

NVD

Vulnerability Analysis

CVE-2026-78425 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2026-78425 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2026-78425

Want to know whenever a new CVE is published for Suse Neuvector? stack.watch will email you.

 

Affected Versions

go github.com/neuvector/neuvector: