Executive brief
NeuVector is a Kubernetes security platform that protects containerized workloads. An authenticated attacker with specific permissions can inject arbitrary OS commands into the privileged container enforcer, gaining complete control of worker nodes and exposing all cluster data. The vulnerability affects multiple versions and requires either authenticated access with Runtime Policies write permission or access to internal gRPC certificates.
Technical details
Improper parameter handling in the packet-capture (sniffer) filter allows OS command injection in the privileged enforcer container. Attack vectors include: (1) any authenticated user with namespaced Runtime Policies (write) permission, or (2) anyone with access to NeuVector's internal gRPC certificate key pair. Successful exploitation leads to arbitrary code execution with container privileges and complete worker node compromise. Patches are available in versions 5.6.2, 5.5.4, 5.4.11 and above.
Affected products
- SUSE NeuVector 5.4 before 5.4.11, 5.5 before 5.5.4, 5.6 before 5.6.2, and potentially older versions
Timeline
- 2026-09-28: disclosed
- 2026-09-16: patched: patches released for versions 5.6.2, 5.5.4, 5.4.11