CVE-2026-25703CWE-202CWE-306CWE-524

CVE-2026-25703

High · published August 5, 2026

CVSS v3.1
7.3
EPSS
0%
Percentile
12.9
In the wild
Unconfirmed
What it is

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00224 · 12.9th percentile
Weaknesses
CWE-202 · Exposure of Sensitive Information Through Data Queries; CWE-306 · Missing Authentication for Critical Function; CWE-524 · Use of Cache Containing Sensitive Information
Published
2026-08-05T14:17Z
References (2)
EPSS history
Timeline
  • 05 AUG 09:48Z
    Potential information leakage from manager /network/graph API in NeuVector
    cvelistv5