CVE-2026-78424: OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NeuVectorto a version that resolves this vulnerability.Fixed in 5.4.11 - Upgrade
Upgrade
NeuVectorto a version that resolves this vulnerability.Fixed in 5.5.4 - Upgrade
Upgrade
NeuVectorto a version that resolves this vulnerability.Fixed in 5.6.2
Event History
Frequently Asked Questions
Who can exploit this issue in a typical deployment?
An authenticated user with namespaced Runtime Policies write permission can exploit it. A party that has obtained NeuVector’s internal gRPC certificate key pair can also exploit it.
What level of access can successful exploitation provide?
Injected commands run in the privileged enforcer container. This can result in complete compromise of the Kubernetes worker node hosting that container.
Which NeuVector releases are affected?
Affected releases are NeuVector 5.4 before 5.4.11, 5.5 before 5.5.4, and 5.6 before 5.6.2. Older versions may also be affected.