Unauthorized VM Control Vulnerability in KubeVirt by OpenShift Metal3
CVE-2026-71566

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-71566?

A vulnerability exists within the KubeVirt environment related to the handling of incoming credentials by the FakeFish component. Instead of validating these credentials appropriately within the platform, KubeVirt uses a KUBECONFIG file that lacks adequate security checks. As a result, any user with access can manipulate instances of VMs associated with FakeFish. This vulnerability allows unauthorized users to start or stop virtual machines and to mount arbitrary CD images, leading to potential data breaches and service disruptions.

Affected Version(s)

fakefish 0 <= 28f9a6b

fakefish 526550a

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.