Unauthorized VM Control Vulnerability in KubeVirt by OpenShift Metal3
CVE-2026-71566
9.3CRITICAL
What is CVE-2026-71566?
A vulnerability exists within the KubeVirt environment related to the handling of incoming credentials by the FakeFish component. Instead of validating these credentials appropriately within the platform, KubeVirt uses a KUBECONFIG file that lacks adequate security checks. As a result, any user with access can manipulate instances of VMs associated with FakeFish. This vulnerability allows unauthorized users to start or stop virtual machines and to mount arbitrary CD images, leading to potential data breaches and service disruptions.
Affected Version(s)
fakefish 0 <= 28f9a6b
fakefish 526550a
