Description
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Policy Bypass
Action: Patch Update
AI Analysis

Impact

The NeuVector admission webhook disregards containers whose image path matches one of three hardcoded service mesh sidecar images, ignoring them during policy evaluation. As a result, any workload author can craft a pod definition with an image path that mimics one of these sidecar images, enabling the container to bypass admission deny rules. This flaw allows unauthorized or malicious containers to be deployed without triggering the intended security checks, potentially exposing the cluster to policy violations and other risks associated with unaudited workloads. The weakness is classified as CWE‑807, indicating improper deferral of service functionality.

Affected Systems

SUSE’s deployment of the NeuVector admission webhook within Kubernetes clusters. Specific vendor: SUSE. Version details are not supplied, so any deployed instance running the unpatched codebase is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation at any given time. This vulnerability is not listed in the CISA KEV catalog. The attack vector can be inferred as remote via the Kubernetes API, since an attacker with deployment privileges can supply the image path. By submitting a pod manifest referencing one of the flagged sidecar images, the broker will silently exclude the container from policy enforcement, giving the attacker the same permissions as the deployer without any detectable policy violation.

Generated by OpenCVE AI on September 28, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NeuVector to the latest version that removes the hardcoded sidecar image exemptions.
  • Configure admission webhook or platform policies to reject or strictly validate image paths that match sidecar image patterns.
  • Modify or disable the sidecar image exemption logic in the admission webhook configuration if an update is not available.

Generated by OpenCVE AI on September 28, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse github.com Neuvector Neuvector
CPEs cpe:2.3:a:suse:github.com_neuvector_neuvector:*:*:*:*:*:*:*:*
Vendors & Products Suse
Suse github.com Neuvector Neuvector
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Neuvector
Neuvector neuvector
Vendors & Products Neuvector
Neuvector neuvector

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
Title Admission Control Bypass via Hardcoded Sidecar Image Exemption
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Neuvector Neuvector
Suse Github.com Neuvector Neuvector
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T12:06:08.210Z

Reserved: 2026-08-24T15:33:13.665Z

Link: CVE-2026-78427

cve-icon Vulnrichment

Updated: 2026-09-17T12:10:38.730Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T10:17:03.637

Modified: 2026-09-28T13:17:22.640

Link: CVE-2026-78427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:00:17Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision