Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. kubevirt.io/kubevirt
  4. ›
  5. CVE-2026-9804

CVE-2026-9804: KubeVirt has a Link Following issue

May 28, 2026 (updated July 1, 2026)

A flaw was found in KubeVirt’s virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod’s filesystem. This leads to information disclosure, potentially exposing sensitive data.

References

  • access.redhat.com/errata/RHSA-2026:27903
  • access.redhat.com/errata/RHSA-2026:27913
  • access.redhat.com/errata/RHSA-2026:27914
  • access.redhat.com/errata/RHSA-2026:27983
  • access.redhat.com/errata/RHSA-2026:28002
  • access.redhat.com/security/cve/CVE-2026-9804
  • bugzilla.redhat.com/show_bug.cgi?id=2482487
  • github.com/advisories/GHSA-mpmf-3w4r-qfpf
  • github.com/kubevirt/kubevirt/commit/6ea563fa94d8ca803f8dd9394cefd8cae36bb0ee
  • nvd.nist.gov/vuln/detail/CVE-2026-9804
  • security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9804.json

Code Behaviors & Features

Detect and mitigate CVE-2026-9804 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.9.0-beta.0

Solution

Unfortunately, there is no solution available yet.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Source file

go/kubevirt.io/kubevirt/CVE-2026-9804.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 00:20:30 +0000.