PT-2026-43242 · Kubevirt+1 · Kubevirt+2

Sarah Bennert

·

Published

2026-05-26

·

Updated

2026-06-15

·

CVE-2026-7374

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KubeVirt (affected versions not specified)
Description A flaw in the virt-handler component allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack the privileged connection of virt-handler. This enables access to any Unix socket on the host, which may lead to full control of the node and the entire cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7374
SUSE-SU-2026:2400-1
SUSE-SU-2026:2401-1

Affected Products

Cri-O
Kubevirt
Openshift