Description
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Published: 2026-09-17
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized continued access
Action: Apply Patch
AI Analysis

Impact

The NeuVector JWT verifier does not enforce canonical Base64URL encoding for the RSA signature field, allowing an attacker holding a valid, non‑expired token to replace the signature bytes with an equivalent but differently encoded version. This flaw lets a user who has logged out of NeuVector continue to use the same token until it expires, effectively bypassing the logout mechanism. The underlying weakness is a failure to validate cryptographic data properly.

Affected Systems

The vulnerability affects the NeuVector platform. No specific product versions are listed in the advisory; users should check for any available updates or patches from the vendor.

Risk and Exploitability

The CVSS v3.1 score is 2, indicating low severity. The EPSS score is below 1%, and the vulnerability is not currently catalogued in CISA KEV. What matters in practice is that an attacker who has already obtained a valid token before logout can reuse it, providing a persistence or credential replay vector until the token’s natural expiration.

Generated by OpenCVE AI on September 28, 2026 at 13:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NeuVector to the latest version that includes the JWT signature canonicalization fix
  • Configure the system to reject noncanonical Base64URL encoded JWT signatures during verification
  • Force a token revocation or re-authentication process immediately after logout to invalidate existing tokens
  • Monitor audit logs for JWT tokens that continue to be used after logout events

Generated by OpenCVE AI on September 28, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse neuvector
CPEs cpe:2.3:a:suse:neuvector:*:*:*:*:*:*:*:*
Vendors & Products Suse
Suse neuvector
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Go
Go neuvector
Vendors & Products Go
Go neuvector

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Title Logout bypass via alternate JWT spelling
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T12:03:54.563Z

Reserved: 2026-08-24T15:33:13.665Z

Link: CVE-2026-78426

cve-icon Vulnrichment

Updated: 2026-09-17T12:40:19.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T10:17:03.520

Modified: 2026-09-28T13:17:22.480

Link: CVE-2026-78426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses