Neuvector SSO Session Mixup in SAML/OIDC (<5.6.1) Auth Hijacking
CVE-2026-78428 Published on September 17, 2026
Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Vulnerability Analysis
CVE-2026-78428 is exploitable with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Products Associated with CVE-2026-78428
Want to know whenever a new CVE is published for Suse Neuvector? stack.watch will email you.