Path Traversal Vulnerability in KubeVirt's VMExport Component
CVE-2026-9804

7.7HIGH

What is CVE-2026-9804?

A security flaw exists in the KubeVirt 'virt-exportserver' component that allows an attacker with specific namespace-level access to exploit a path traversal vulnerability. By creating a symbolic link within the exported filesystem Persistent Volume Claim (PVC) that points to locations outside its designated mount root, an attacker can gain unauthorized access to arbitrary files within the exporter pod's filesystem. This could lead to the disclosure of sensitive information, potentially compromising system integrity and confidentiality.

Affected Version(s)

Red Hat Container Native Virtualization 4.17 1781757410

Red Hat Container Native Virtualization 4.18 1781928221

Red Hat Container Native Virtualization 4.19 1781590993

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Thai Son Dinh, GitHub: @sondt99 (VinSOC) for reporting this issue.
.