Path Traversal Vulnerability in KubeVirt's VMExport Component
CVE-2026-9804
Key Information:
What is CVE-2026-9804?
A security flaw exists in the KubeVirt 'virt-exportserver' component that allows an attacker with specific namespace-level access to exploit a path traversal vulnerability. By creating a symbolic link within the exported filesystem Persistent Volume Claim (PVC) that points to locations outside its designated mount root, an attacker can gain unauthorized access to arbitrary files within the exporter pod's filesystem. This could lead to the disclosure of sensitive information, potentially compromising system integrity and confidentiality.
Affected Version(s)
Red Hat Container Native Virtualization 4.17 1781757410
Red Hat Container Native Virtualization 4.18 1781928221
Red Hat Container Native Virtualization 4.19 1781590993
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved