CVE-2026-78426

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.

  • Published Sep 17, 2026
  • CVSS 2.0 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78426 at the National Vulnerability Database