CVE-2026-78426
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Sep 17, 2026
Vendor
unknown
Description
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.