CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9804: Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

highCVSS 7.7CVE-2026-9804

CSIRTS triage

What
A symlink escape vulnerability in vmexport allows the exporter pod to read arbitrary files from the host filesystem.
Who is affected
Kubernetes clusters running KubeVirt with vmexport functionality exposed to untrusted users.
Urgency
High severity (CVSS 7.7) enabling unauthorized file access; not currently exploited.
Action
Upgrade KubeVirt to a patched version or restrict vmexport pod file system permissions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch KubeVirt

Get an email when a new KubeVirt advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
high — CVSS 7.7
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9804

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-9804coverage & exploitation statusNVD · CVE.org

Recent advisories for Kubevirt

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center