CVE-2025-14459: Authorization Bypass Through User-Controlled Key in Red Hat RHEL-9-CNV-4.19
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.
AI Analysis
Technical Summary
This vulnerability in KubeVirt CDI enables an authorization bypass that permits a user with limited privileges to clone PVCs from unauthorized namespaces. The flaw is due to insufficient access control checks on the DataImportCron PVC source, allowing unauthorized data access. The issue is tracked as CVE-2025-14459 with a CVSS v3.1 score of 8.5 (high severity), indicating network attack vector, low attack complexity, privileges required, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact. Red Hat has released OpenShift Virtualization 4.19.17 images that include fixes for this and other vulnerabilities.
Potential Impact
Successful exploitation allows an attacker with limited privileges to access and clone PVCs from namespaces they should not have access to, resulting in unauthorized disclosure of potentially sensitive data. The confidentiality impact is high, while integrity impact is low and availability is unaffected. This could lead to data leakage across tenant boundaries in multi-tenant Kubernetes/OpenShift environments.
Mitigation Recommendations
Red Hat has released OpenShift Virtualization 4.19.17 images that fix this vulnerability. Users should apply this update to remediate the issue. Before applying this update, ensure all previously released relevant errata are applied. Refer to Red Hat's official advisory at https://access.redhat.com/errata/RHSA-2026:0950 and https://access.redhat.com/security/cve/CVE-2025-14459 for detailed update instructions and confirmation of the fix. No alternative mitigations or workarounds are specified in the advisory.
CVE-2025-14459: Authorization Bypass Through User-Controlled Key in Red Hat RHEL-9-CNV-4.19
Description
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.
CVSS v3.1
Score 8.5high
Affected software
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
RHEL-9-CNV-4.19
Red Hat
Red Hat OpenShift Virtualization 4
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in KubeVirt CDI enables an authorization bypass that permits a user with limited privileges to clone PVCs from unauthorized namespaces. The flaw is due to insufficient access control checks on the DataImportCron PVC source, allowing unauthorized data access. The issue is tracked as CVE-2025-14459 with a CVSS v3.1 score of 8.5 (high severity), indicating network attack vector, low attack complexity, privileges required, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact. Red Hat has released OpenShift Virtualization 4.19.17 images that include fixes for this and other vulnerabilities.
Potential Impact
Successful exploitation allows an attacker with limited privileges to access and clone PVCs from namespaces they should not have access to, resulting in unauthorized disclosure of potentially sensitive data. The confidentiality impact is high, while integrity impact is low and availability is unaffected. This could lead to data leakage across tenant boundaries in multi-tenant Kubernetes/OpenShift environments.
Mitigation Recommendations
Red Hat has released OpenShift Virtualization 4.19.17 images that fix this vulnerability. Users should apply this update to remediate the issue. Before applying this update, ensure all previously released relevant errata are applied. Refer to Red Hat's official advisory at https://access.redhat.com/errata/RHSA-2026:0950 and https://access.redhat.com/security/cve/CVE-2025-14459 for detailed update instructions and confirmation of the fix. No alternative mitigations or workarounds are specified in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2025-12-10T15:18:02.606Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2026:0950","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-14459","vendor":"Red Hat"}]
Threat ID: 6977c5a14623b1157cb6ff8a
Added to database: 01/26/2026, 19:50:57 UTC
Last enriched: 07/15/2026, 08:16:41 UTC
Last updated: 09/10/2026, 22:18:47 UTC
Views: 182
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.