VYPR
Critical severity9.9NVD Advisory· Published May 26, 2026· Updated Aug 24, 2026

CVE-2026-7374

CVE-2026-7374

Description

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
kubevirt.io/kubevirtGo
>= 1.8.0-alpha.0, < 1.8.31.8.3
kubevirt.io/kubevirtGo
>= 1.7.0-alpha.0, < 1.7.41.7.4
kubevirt.io/kubevirtGo
< 1.6.61.6.6

Affected products

13

Patches

Vulnerability mechanics

References

17

News mentions

0

No linked articles in our index yet.