CVE-2026-9804: Red Hat Container Native Virtualization 4.17

High severity, CVSS 7.7. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

Affected products

  • Red Hat Red Hat Container Native Virtualization 4.17: before 1781757410 (fixed in 1781757410)
  • Red Hat Red Hat Container Native Virtualization 4.18: before 1781928221 (fixed in 1781928221)
  • Red Hat Red Hat Container Native Virtualization 4.19: before 1781590993 (fixed in 1781590993)
  • Red Hat Red Hat Container Native Virtualization 4.20: before 1781838712 (fixed in 1781838712)
  • Red Hat Red Hat Container Native Virtualization 4.21: before 1782012918 (fixed in 1782012918)
  • Red Hat Red Hat Openshift Virtualization 4

Published 2026-05-28. Last modified 2026-09-10.