CVE-2026-78426EPSS p7.5%
CVE-2026-78426CVE-2026-78426
Description
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Scoring
| EPSS | 0.19% probability of exploitation · percentile 7.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |