CVE-2025-67860: Suse Harvester
Low severity, CVSS 3.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.
Affected products
- Suse Harvester: from 4.0, before 4.072 (fixed in 4.072)
Published 2026-02-25. Last modified 2026-06-17.