Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-9804

32
FAUCET Score

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

First published: May 28, 2026Last modified: Jul 19, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat OpenShift Virtualization 4
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Container Native Virtualization 4.17
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Container Native Virtualization 4.18
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Container Native Virtualization 4.19
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Container Native Virtualization 4.2
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
40.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 30th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/virt-exportserver
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/virt-exportserver-rhel9

Vendor Advisories (3)

goGHSA-mpmf-3w4r-qfpfhigh

KubeVirt has a Link Following issue

May 28, 2026
redhatCVE-2026-9804Important

kubevirt: kubevirt: VMExport directory symlink escape enables exporter pod file read

May 28, 2026
microsoft2026-May/CVE-2026-9804Important

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

May 12, 2026

References

security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-9804.json
access.redhat.com / errata/RHSA-2026:27903
access.redhat.com / errata/RHSA-2026:27913
access.redhat.com / errata/RHSA-2026:27914
access.redhat.com / errata/RHSA-2026:27983
access.redhat.com / errata/RHSA-2026:28002
access.redhat.com / security/cve/CVE-2026-9804
bugzilla.redhat.com / show_bug.cgi