Description
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
Published: 2026-05-28
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in KubeVirt’s virt-exportserver allows an attacker with namespace‑level privileges to create a symbolic link inside an exported Persistent Volume Claim that points outside the intended mount root. The exporter pod can resolve the link and read files on its own filesystem, exposing arbitrary sensitive content. This results in information disclosure.

Affected Systems

The vulnerability affects Red Hat OpenShift Virtualization 4, specifically the KubeVirt virt-exportserver component that runs inside the exporter pod. All deployments of this component are impacted unless software is updated to a version that contains the fix.

Risk and Exploitability

The flaw carries a CVSS score of 7.7, indicating a high‑severity risk. The EPSS score is not published, and it is not listed in the CISA KEV catalog, leaving the exact exploit probability unclear. However, because the attacker only requires namespace‑level access and the ability to write a symbolic link, the attack is realistic in many cluster configurations. The potential to read arbitrary files from the exporter pod’s filesystem elevates the risk to confidentiality and could support lateral movement if privileged data is exposed.

Generated by OpenCVE AI on May 28, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Red Hat OpenShift Virtualization 4 that addresses CVE‑2026‑9804.
  • Ensure that only authorized users can create symbolic links in exported persistent volume claims; consider tightening RBAC for namespace‑level access.
  • Validate or cleanse exported filesystems for stray symbolic links before export to prevent path traversal.

Generated by OpenCVE AI on May 28, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 28 May 2026 08:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
Title Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
First Time appeared Redhat
Redhat container Native Virtualization
Weaknesses CWE-59
CPEs cpe:/a:redhat:container_native_virtualization:4
Vendors & Products Redhat
Redhat container Native Virtualization
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Container Native Virtualization
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-05-30T01:54:43.739Z

Reserved: 2026-05-28T06:10:07.134Z

Link: CVE-2026-9804

cve-icon Vulnrichment

Updated: 2026-05-30T01:54:38.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T09:16:49.500

Modified: 2026-05-28T13:44:54.327

Link: CVE-2026-9804

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-28T06:00:00Z

Links: CVE-2026-9804 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T10:00:11Z

Weaknesses