CVE-2025-67860
published 2026-02-25CVE-2025-67860: A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments…
PriorityP414low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.09%
0.6th percentile
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | neuvector_scanner | >= 4.0 < 4.072 | 4.072 |
| suse | harvester | >= 4.0 < 4.072 | 4.072 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
NeuVector scanner insecurely handles passwords as command arguments in github.com/neuvector/scanner
osv·2026-02-17
CVE-2025-67860 NeuVector scanner insecurely handles passwords as command arguments in github.com/neuvector/scanner
NeuVector scanner insecurely handles passwords as command arguments in github.com/neuvector/scanner
NeuVector scanner insecurely handles passwords as command arguments in github.com/neuvector/scanner.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/neuvector/scanner before 4.072.
OSV
NeuVector scanner insecurely handles passwords as command arguments
osv·2026-02-12
CVE-2025-67860 [LOW] NeuVector scanner insecurely handles passwords as command arguments
NeuVector scanner insecurely handles passwords as command arguments
### Impact
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This may allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment.
**Important:**
- For the exposure of credentials not related to Rancher NeuVector, the final impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.
- It is recommended to review for potentially leaked credentials in thi
GHSA
NeuVector scanner insecurely handles passwords as command arguments
ghsa·2026-02-12
CVE-2025-67860 [LOW] CWE-522 NeuVector scanner insecurely handles passwords as command arguments
NeuVector scanner insecurely handles passwords as command arguments
### Impact
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This may allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment.
**Important:**
- For the exposure of credentials not related to Rancher NeuVector, the final impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.
- It is recommended to review for potentially leaked credentials in thi
No detection rules found.
No public exploits indexed.
2026-02-25
Published