CVE-2026-9804 Details
Description
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.
A path traversal vulnerability has been identified in the virt-exportserver component of KubeVirt. This issue allows an attacker with specific namespace-level access to exploit the VMExport directory endpoint. By placing a symbolic link within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This vulnerability leads to information disclosure, potentially exposing sensitive data. The issue affects PVCs that do not have the appropriate KubeVirt content type annotation, with namespaces containing mixed workloads being more susceptible.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | redhat-SADP |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
39 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | redhat-SADP |
| Sep 9, 2026 | CVE Modified | [email protected] |
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 8, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 22, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Aug 13, 2026 | CVE Modified | [email protected] |
| Aug 10, 2026 | CVE Modified | redhat-SADP |
| Aug 9, 2026 | CVE Modified | [email protected] |
| Aug 9, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | redhat-SADP |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Aug 2, 2026 | CVE Modified | [email protected] |
| Jul 28, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | [email protected] |
| Jul 26, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | CVE Modified | redhat-SADP |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 19, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |