Junglewise Threat Intelligence

CVE-2026-78427: NeuVector admission webhook policy bypass via hardcoded sidecar image exemption

CVE-2026-78427 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Technologies: Suse NeuVector. Vendors: Suse.

Executive brief

NeuVector is a container security platform that uses an admission webhook to enforce security policies on Kubernetes workloads. The webhook contains a vulnerability where it automatically exempts three hardcoded service mesh sidecar image names from policy evaluation. An attacker with workload deployment privileges can bypass admission denial rules by simply naming their container image to match one of these exempted sidecar images, allowing unauthorized containers to run without security policy enforcement.

Technical details

The vulnerability is a reliance on untrusted inputs in a security decision (CWE-807). The NeuVector admission webhook checks container image paths against three hardcoded sidecar image names and silently exempts matching containers from policy evaluation. Since the image path is entirely controlled by the workload author (a user deploying to Kubernetes), any user with deployment privileges can craft a malicious container image with a path matching one of the hardcoded exemptions to bypass admission deny rules. The attack requires low privileges (ability to deploy workloads) and no user interaction, with a network attack vector against the webhook. Patches are available in NeuVector v5.6.2, v5.5.4, v5.4.11 and later, which remove the automatic sidecar exemptions entirely.

Affected products

  • SUSE NeuVector <=5.6.1

Timeline

  • 2026-09-16: disclosed
  • 2026-09-17: patched: Patched in v5.6.2, v5.5.4, v5.4.11 and above

References

Related threats