CVE-2026-9804: Improper Link Resolution Before File Access ('Link Following') in Red Hat Red Hat Container Native Virtualization 4.17
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
AI Analysis
Technical Summary
A path traversal vulnerability exists in the virt-exportserver component of KubeVirt used in Red Hat Container Native Virtualization. The flaw allows an attacker with namespace-level access to place symbolic links within an exported filesystem PVC that reference files outside the mount root. This improper link resolution before file access enables reading arbitrary files from the exporter pod's filesystem, resulting in information disclosure. The vulnerability affects multiple versions of Red Hat Container Native Virtualization including 4.17, 4.19, 4.20, and 4.21. Red Hat has issued security advisories (RHSA-2026:27914) and released updated images in OpenShift Virtualization v4.19 to address this issue.
Potential Impact
Successful exploitation allows an attacker with namespace-level privileges to read arbitrary files from the exporter pod's filesystem by leveraging symbolic links in PVC exports. This leads to information disclosure with high confidentiality impact. There is no impact on integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated OpenShift Virtualization v4.19 images that fix this vulnerability. Users should apply these updates after ensuring all previously released errata relevant to their systems have been applied. Refer to Red Hat's official advisory RHSA-2026:27914 and the update instructions at https://access.redhat.com/articles/11258 for detailed remediation guidance. No temporary or alternative mitigations are specified.
CVE-2026-9804: Improper Link Resolution Before File Access ('Link Following') in Red Hat Red Hat Container Native Virtualization 4.17
Description
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
CVSS v3.1
Score 7.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A path traversal vulnerability exists in the virt-exportserver component of KubeVirt used in Red Hat Container Native Virtualization. The flaw allows an attacker with namespace-level access to place symbolic links within an exported filesystem PVC that reference files outside the mount root. This improper link resolution before file access enables reading arbitrary files from the exporter pod's filesystem, resulting in information disclosure. The vulnerability affects multiple versions of Red Hat Container Native Virtualization including 4.17, 4.19, 4.20, and 4.21. Red Hat has issued security advisories (RHSA-2026:27914) and released updated images in OpenShift Virtualization v4.19 to address this issue.
Potential Impact
Successful exploitation allows an attacker with namespace-level privileges to read arbitrary files from the exporter pod's filesystem by leveraging symbolic links in PVC exports. This leads to information disclosure with high confidentiality impact. There is no impact on integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released updated OpenShift Virtualization v4.19 images that fix this vulnerability. Users should apply these updates after ensuring all previously released errata relevant to their systems have been applied. Refer to Red Hat's official advisory RHSA-2026:27914 and the update instructions at https://access.redhat.com/articles/11258 for detailed remediation guidance. No temporary or alternative mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:27914
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-35469"]
- Cvss Version
- 3.1
Threat ID: 6a395a04eed863c81e08e2f8
Added to database: 06/22/2026, 15:51:32 UTC
Last enriched: 08/03/2026, 00:55:36 UTC
Last updated: 08/06/2026, 15:07:28 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.