CVE-2026-78426
EUVD-2026-8141417.09.2026, 10:17
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.