CVE-2026-9804
HIGHCVSS 7.7/10EPSS 0.50%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-9804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
