Description
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Session Hijacking / Impersonation
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Neuvector allows one user to acquire another user's authenticated session when multiple SAML or OpenID Connect login attempts happen concurrently. The flaw results in an unauthorized session takeover, giving the attacker full access to the victim’s account. This issue is a classic case of session fixation (CWE-384) and directly compromises confidentiality and integrity of user data.

Affected Systems

The affected product is Neuvector from SUSE, version 5.6.1. Any installation that relies on SAML or OIDC authentication may be impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability, but the EPSS score of less than 1% shows a very low probability of exploitation at this time. The vulnerability is not currently listed in CISA’s KEV table. Although no specific exploitation environment is detailed, the likely vector involves feeding concurrent login requests to the SSO endpoint, enabling session collision. The impact is limited to individual accounts and not to system-wide compromise unless orchestration or privileged user accounts are involved.

Generated by OpenCVE AI on September 28, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Neuvector release that addresses the session fixation flaw as soon as it becomes available.
  • Configure SSO to enforce a one-to-one mapping between authenticated users and session tokens, and reject any session that would replace an existing one for a different account.
  • Monitor authentication logs for anomalous session assignments and investigate any case where a user’s session is unexpectedly replaced by another.

Generated by OpenCVE AI on September 28, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
First Time appeared Suse
Suse neuvector
CPEs cpe:2.3:a:suse:neuvector:_5.6.1:*:*:*:*:*:*:*
Vendors & Products Suse
Suse neuvector
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H'}


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Go
Go neuvector
Vendors & Products Go
Go neuvector

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-384

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Title Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T12:07:55.498Z

Reserved: 2026-08-24T15:33:13.665Z

Link: CVE-2026-78428

cve-icon Vulnrichment

Updated: 2026-09-17T12:15:09.895Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T10:17:03.760

Modified: 2026-09-28T13:17:22.800

Link: CVE-2026-78428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:00:17Z

Weaknesses