CVE-2026-78428 PUBLISHED

Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

Assigner: suse
Reserved: 24.08.2026 Published: 17.09.2026 Updated: 17.09.2026

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8

Product Status

Vendor go
Product neuvector
Versions Default: unaffected
  • Version <5.6.1 is affected

References