CVE-2025-67860: Suse Harvester

Low severity, CVSS 3.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.

Affected products

  • Suse Harvester: from 4.0, before 4.072 (fixed in 4.072)

Published 2026-02-25. Last modified 2026-06-17.