PT-2026-7954 · Neuvector · Neuvector

Published

2026-02-12

·

Updated

2026-03-03

·

CVE-2025-67860

CVSS v3.1

3.8

Low

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NeuVector versions prior to 4.072
Description The NeuVector scanner insecurely handles passwords as command arguments. The scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This could allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment. The impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.
Recommendations Upgrade to NeuVector scanner version 4.072 or later.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-67860
GHSA-3C9M-GQ32-G4JX
GO-2026-4490
SUSE-SU-2026:0757-1

Affected Products

Neuvector