CVE-2026-78426: Suse Neuvector

Low severity, CVSS 2.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.

Affected products

  • Suse Neuvector: up to and including v5.6.1

Published 2026-09-17. Last modified 2026-09-28.