CVE-2026-12080 Details
Description
A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.
A local unprivileged user can exploit a vulnerability in the QEMU Guest Agent (qga) by manipulating symbolic links. This issue arises in the guest-ssh-add-authorized-keys command handler, where the agent, running as root, follows symlinks in a way that can be exploited. The vulnerability can be triggered through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer, such as libvirt, to activate the affected code path.
If the guest-ssh-add-authorized-keys command is not needed, it can be disabled by adding it to the QEMU Guest Agent block list. This will prevent the vulnerable code path from being executed while maintaining other guest-agent functionalities.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | New CVE Received | [email protected] |