Junglewise Threat Intelligence

CVE-2026-78425: NeuVector SAML audience confusion authentication bypass

CVE-2026-78425 · Severity: info · CVSS 7.6 · Published 2026-09-17

Technologies: NeuVector.

Executive brief

NeuVector is a container security platform that uses SAML single sign-on (SSO) to authenticate users through corporate identity providers. A flaw in SAML assertion validation allows employees authorized for other applications (like wikis, ticketing systems, or expense tools) to log into NeuVector if they share the same corporate identity provider, without requiring any additional credentials. This can lead to unauthorized access by employees who should not have NeuVector access.

Technical details

NeuVector's SAML SSO implementation fails to properly validate the SAML Audience element, which is meant to restrict an assertion to a specific service provider (SP). When a user authenticates via a corporate identity provider (IdP), the IdP issues an assertion containing an Audience field tied to a different application (e.g., a wiki or ticketing system). NeuVector receives this assertion but does not enforce the Audience restriction—it only logs a `NotInAudience` warning that goes unread. An attacker with legitimate credentials for any other SAML-enabled application behind the same IdP can present that application's SAML assertion to NeuVector and gain unauthorized access. The vulnerability requires the attacker to have valid credentials for another SAML-backed application and network access to NeuVector. Patches are available in v5.6.2, v5.5.4, v5.4.11 and later, which introduce configurable Audience URI validation.

Affected products

  • NeuVector NeuVector <=5.6.1

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Patches released: v5.6.2, v5.5.4, v5.4.11

References