Back

HIGH

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

Published May 28, 2026

Description

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 28, 2026
Updated Sep 10, 2026
Reserved May 28, 2026
CISA Vulnrichment
Updated May 30, 2026
NVD
Status Awaiting Analysis
Modified Sep 10, 2026
Red Hat
Severity Important
Public date May 28, 2026
GHSA-MPMF-3W4R-QFPF