PT-2026-43242 · Kubevirt+1 · Kubevirt+2
Sarah Bennert
·
Published
2026-05-26
·
Updated
2026-06-15
·
CVE-2026-7374
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KubeVirt (affected versions not specified)
Description
A flaw in the
virt-handler component allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack the privileged connection of virt-handler. This enables access to any Unix socket on the host, which may lead to full control of the node and the entire cluster.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cri-O
Kubevirt
Openshift