Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sarah Bennert

#23943of 53,632
9.9Total CVSS
Vulnerabilities · 1
PT-2026-43242
9.9
2026-05-26
Kubevirt · Kubevirt · CVE-2026-7374
**Name of the Vulnerable Software and Affected Versions** KubeVirt (affected versions not specified) **Description** A flaw in the `virt-handler` component allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack the privileged connection of `virt-handler`. This enables access to any Unix socket on the host, which may lead to full control of the node and the entire cluster. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.