VYPR
High severity7.7NVD Advisory· Published May 28, 2026· Updated Aug 24, 2026

CVE-2026-9804

CVE-2026-9804

Description

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
kubevirt.io/kubevirtGo
<= 1.9.0-beta.0

Affected products

12

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.