PT-2026-44221 · Kubevirt · Kubevirt

CVE-2026-9804

·

Published

2026-05-28

·

Updated

2026-07-30

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KubeVirt versions prior to 1.8.3-1.1
Description A path traversal flaw exists in the virt-exportserver component. An attacker with namespace-level access can exploit the 'VMExport directory' endpoint by placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root. This allows the attacker to read arbitrary files from the exporter pod's filesystem, resulting in information disclosure of sensitive data.
Recommendations Update to version 1.8.3-1.1.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9804
GHSA-MPMF-3W4R-QFPF
GO-2026-5883
OPENSUSE-SU-2026:11015-1
OPENSUSE-SU-2026:11057-1
OPENSUSE-SU-2026:11091-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:2783-1
SUSE-SU-2026:2804-1

Affected Products

Kubevirt