CVE-2026-9804
published 2026-05-28CVE-2026-9804: A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the…
PriorityP351high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
0.52%
41.5th percentile
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| container-native-virtualization | virt-exportserver | — | — |
| container-native-virtualization | virt-exportserver-rhel9 | — | — |
| kubevirt.io | kubevirt | 0 – 1.9.0-beta.0 | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kubevirt: kubevirt: VMExport directory symlink escape enables exporter pod file read
vendor_redhat·2026-05-28·CVSS 7.7
CVE-2026-9804 [HIGH] CWE-59 kubevirt: kubevirt: VMExport directory symlink escape enables exporter pod file read
kubevirt: kubevirt: VMExport directory symlink escape enables exporter pod file read
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
Package: container-native-virtualization/virt-exportserver (Red Hat OpenShift Virtualization 4) - Affected
Package: container-native-virtualization/virt-exportserver-rhel9 (Red Hat OpenShift Virtualization 4) - Affected
VulDB
KubeVirt virt-exportserver link following (EUVD-2026-32748 / Nessus ID 326001)
vuldb·2026-07-12·CVSS 7.7
CVE-2026-9804 [HIGH] KubeVirt virt-exportserver link following (EUVD-2026-32748 / Nessus ID 326001)
A vulnerability, which was classified as critical, was found in KubeVirt. The affected element is an unknown function of the component virt-exportserver. Such manipulation leads to link following.
This vulnerability is documented as CVE-2026-9804. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-mpmf-3w4r-qfpf: A flaw was found in KubeVirt's virt-exportserver component
ghsa_unreviewed·2026-05-28
CVE-2026-9804 [HIGH] CWE-59 GHSA-mpmf-3w4r-qfpf: A flaw was found in KubeVirt's virt-exportserver component
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
GHSA
KubeVirt has a Link Following issue
ghsa·2026-05-28
CVE-2026-9804 [HIGH] CWE-59 KubeVirt has a Link Following issue
KubeVirt has a Link Following issue
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:27903https://access.redhat.com/errata/RHSA-2026:27913https://access.redhat.com/errata/RHSA-2026:27914https://access.redhat.com/errata/RHSA-2026:27983https://access.redhat.com/errata/RHSA-2026:28002https://access.redhat.com/security/cve/CVE-2026-9804https://bugzilla.redhat.com/show_bug.cgi?id=2482487https://access.redhat.com/errata/RHSA-2026:27903https://access.redhat.com/errata/RHSA-2026:27913https://access.redhat.com/errata/RHSA-2026:27914https://access.redhat.com/errata/RHSA-2026:27983https://access.redhat.com/errata/RHSA-2026:28002https://access.redhat.com/security/cve/CVE-2026-9804https://bugzilla.redhat.com/show_bug.cgi?id=2482487https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9804.json
2026-05-28
Published