Description
An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log






This issue affects neuvector: before 5.4.5.
Published: 2026-09-09
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insertion of sensitive information into log files caused SUSE NeuVector’s manager container to expose confidential data. The flaw violates the confidentiality of stored credentials, tokens, or other secrets, pursuant to the Common Weakness Enumeration CWE‑532. This leads to a breach of privacy and may enable attackers to leverage the leaked data for further intrusion or account compromises.

Affected Systems

The vulnerability affects the SUSE NeuVector manager component. Any deployment using a NeuVector version earlier than 5.4.5 is susceptible. The issue is confined to the manager container instance and its associated log files.

Risk and Exploitability

With a CVSS score of 6.8, the vulnerability is considered medium severity. Although an EPSS score is not available, the lack of a CISA KEV listing indicates no known large‑scale exploitation as of now. The likely attack vector is an attacker who can influence the manager to log sensitive data—either through a local compromise or by manipulating application inputs that trigger logging paths. The risk is elevated for environments where logs are accessible to privileged users or exposed externally.

Generated by OpenCVE AI on September 9, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NeuVector manager to version 5.4.5 or later to eliminate the logging flaw
  • If an immediate upgrade is not possible, configure the manager to suppress or redact sensitive data before writing to logs, and ensure log files are stored in a location inaccessible to unauthorized parties
  • Audit existing log files for exposed credentials or secrets, purge or mask any sensitive entries, and monitor future logs for unintended disclosures

Generated by OpenCVE AI on September 9, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
Title Sensitive information is leaked into NeuVector’s manager container logs
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-09T08:25:42.467Z

Reserved: 2025-04-30T11:28:04.728Z

Link: CVE-2025-46808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T09:17:10.013

Modified: 2026-09-09T09:17:10.013

Link: CVE-2025-46808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:15:09Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File