CVE-2026-27211 is a critical vulnerability affecting Cloud Hypervisor versions 34.0 through 50.0, allowing arbitrary host file exfiltration when using virtio-block devices backed by raw images. A malicious guest can craft a QCOW2 header to point to sensitive host paths, which the image format auto-detection then parses upon VM reboot or disk scan, serving the host file's contents to the guest. This vulnerability has a CVSS score of 10.0 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, requiring either a writable backing image or an untrusted image source for successful exploitation. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 34.0, < 50.1CPE matchmatch criteria | cpe:2.3:a:cloudhypervisor:cloud_hypervisor:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.