Description
An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log






This issue affects neuvector: before 5.4.5.
Published: 2026-09-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure (log data leak)
Action: Update
AI Analysis

Impact

An insertion of sensitive information into log files caused SUSE NeuVector’s manager container to expose confidential data. The flaw violates the confidentiality of stored credentials, tokens, or other secrets, pursuant to the Common Weakness Enumeration CWE‑532. This leads to a breach of privacy and may enable attackers to leverage the leaked data for further intrusion or account compromises.

Affected Systems

The vulnerability affects the SUSE NeuVector manager component. Any deployment using a NeuVector version earlier than 5.4.5 is susceptible. The issue is confined to the manager container instance and its associated log files.

Risk and Exploitability

With a CVSS score of 6.8, the vulnerability is considered medium severity. Although an EPSS score is not available, the lack of a CISA KEV listing indicates no known large‑scale exploitation as of now. The likely attack vector is an attacker who can influence the manager to log sensitive data—either through a local compromise or by manipulating application inputs that trigger logging paths. The risk is elevated for environments where logs are accessible to privileged users or exposed externally.

Generated by OpenCVE AI on September 9, 2026 at 10:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NeuVector manager to version 5.4.5 or later to eliminate the logging flaw
  • If an immediate upgrade is not possible, configure the manager to suppress or redact sensitive data before writing to logs, and ensure log files are stored in a location inaccessible to unauthorized parties
  • Audit existing log files for exposed credentials or secrets, purge or mask any sensitive entries, and monitor future logs for unintended disclosures

Generated by OpenCVE AI on September 9, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse neuvector
Vendors & Products Suse
Suse neuvector

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
Title Sensitive information is leaked into NeuVector’s manager container logs
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-10T14:06:23.527Z

Reserved: 2025-04-30T11:28:04.728Z

Link: CVE-2025-46808

cve-icon Vulnrichment

Updated: 2026-09-10T14:06:18.997Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-09T09:17:10.013

Modified: 2026-09-10T15:17:24.780

Link: CVE-2025-46808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:15:13Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File