What is CVE-2026-25703?
CVE-2026-25703 potentially allows information leakage from the manager /network/graph API in NeuVector through version 5.4.9 due to missing authentication and cached sensitive data. Affected deployments should enforce API access controls and review cache configuration to mitigate the risk.
Azərbaycanca: CVE-2026-25703 NeuVector 5.4.9-a qədər versiyalarda manager /network/graph API-də autentifikasiyanın olmaması səbəbindən kəşlənmiş həssas məlumatların sızmasına yol aça bilər. Bu boşluq şəbəkə qrafiki API-sindən mühafizəsiz məlumat sızması riski yaradır. Təsirə məruz qalan sistemlərdə API giriş nəzarətini gücləndirmək və kəş mexanizmlərini konfiqurasiya etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of NeuVector are affected by CVE-2026-25703?
This vulnerability affects NeuVector versions up to and including 5.4.9.
What is the root cause of CVE-2026-25703?
The vulnerability is caused by missing authentication on the manager /network/graph API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.