CVE-2026-9804

Aliases:GHSA-mpmf-3w4r-qfpfGO-2026-5883CGA-cx9c-85rh-3452CGA-2675-77qg-5f34CGA-2hg7-q5qh-6qv5CGA-2m7g-h66g-fgx2CGA-2qpx-p7vg-pr6qCGA-34vr-wm65-q35pCGA-3757-mgv8-r43cCGA-38f4-xx57-2xpxCGA-38mf-25rc-964fCGA-3gjh-x3xm-jf54CGA-3jjw-9vmg-cph2CGA-3jxx-68gq-rjvmCGA-3qrg-6qv3-8fv5CGA-43rm-h524-9fwgCGA-496p-gg6f-4674CGA-4h35-fgj7-gq9hCGA-5264-jrcm-43frCGA-5353-722f-3qg9CGA-554v-g5f9-6m6rCGA-5g79-3875-w6xqCGA-5v8h-75fj-mwwfCGA-5vjc-jfwq-w5ppCGA-65wq-3f7p-5v86CGA-69pp-87m5-9pr2CGA-6fg4-xh53-wxxrCGA-6gm7-5r52-m23jCGA-6hm2-vjrm-fc57CGA-6jxm-5v2c-cj36CGA-6mr7-cfcf-3h2qCGA-6wx7-6v3c-56r8CGA-73vj-mvc9-4333CGA-77mm-wqf9-c236CGA-7f2x-rcgh-3cx8CGA-7xc8-q3cr-mr4vCGA-8g3p-g6q7-372gCGA-8rwx-244c-cqmpCGA-8w43-w3h9-7fvrCGA-9482-6qv8-mxqpCGA-94wp-96mv-h3gpCGA-9vjr-h67r-gc63CGA-c446-mxmr-f945CGA-c77v-rxjr-r55mCGA-cfgf-xr39-vvmpCGA-cpfg-768j-4855CGA-cqpp-363h-63wgCGA-cqr3-pqm3-p25mCGA-cwr8-vvc9-fc3jCGA-cxpq-35fh-3c9wCGA-fh27-v87m-xch7CGA-fjwx-hg92-gr37CGA-fwp5-p4rj-cc99CGA-fwr9-v867-rv7xCGA-g28q-gp4m-vx6gCGA-g69p-rv22-v798CGA-g8xf-9pjv-5fvwCGA-gr45-g8r3-mgqmCGA-grv3-92fv-jq6gCGA-gvqg-hpj9-w2ppCGA-h275-358c-9c3fCGA-hffm-h9cx-gvrrCGA-hh7v-2q58-3p39CGA-hhvm-gv64-hvw7CGA-hvmh-gp4p-3pv9CGA-hwcw-pcp7-xm3vCGA-j26g-fcvg-prwvCGA-j5c7-7q68-2w9cCGA-jr78-hf4p-3v9hCGA-m37f-xqpf-fgv4CGA-m669-m54x-8pghCGA-m9cm-44r6-gjx9CGA-mffw-c94v-74v7CGA-mgv3-qf3w-6q9vCGA-p586-c4jp-pgr5CGA-pfmm-mgxw-m54pCGA-pvfr-2w73-fhv7CGA-qhpf-w8gf-8grrCGA-qphq-7vxj-gmfmCGA-qqw6-v472-g43mCGA-qx75-r8r6-56qgCGA-rggx-rxj9-rw86CGA-rv6h-g42g-4mvgCGA-rx5g-8fx9-v2m6CGA-rxjj-f2gp-6q7xCGA-v2gw-5f7g-4w3gCGA-vppv-x64p-557wCGA-vw89-px8h-x6pvCGA-vxc9-75hg-wv36CGA-w4j3-f8f4-8fc3CGA-x5m5-r496-g6rrCGA-x8g5-8jpf-gv44CGA-x9p4-mphr-vf47CGA-xxqx-jr86-cqr8
Awaiting Analysis
Published: 28 May 2026, 08:15
Last modified:10 Sept 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.7 HIGH
v3.1 (cve.org)
EPSS Score
0.52% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 May 2026, 08:15
Published
Vulnerability first disclosed
10 Sept 2026, 12:05
Last Modified
Vulnerability information updated

Description

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

CVSS Metrics

  • v3.1HIGHScore: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.52% Percentile: 43%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • chainguarddocker-machine-driver-harvester

    all

  • chainguardharvester

    all

  • chainguardharvester-fips

    all

  • chainguardharvester-fips-upgrade-helper

    all

  • chainguardharvester-fips-webhook

    all

  • chainguardharvester-upgrade-helper

    all

  • chainguardharvester-webhook

    all

  • chainguardvirt-api-1.6

    < 0

  • chainguardvirt-api-1.7

    < 0

  • chainguardvirt-api-1.8

    < 0

  • chainguardvirt-api-fips-1.6

    < 0

  • chainguardvirt-api-fips-1.7

    < 0

  • chainguardvirt-api-fips-1.8

    < 0

  • chainguardvirt-chroot-1.6

    < 0

  • chainguardvirt-chroot-1.7

    < 0

  • chainguardvirt-chroot-1.8

    < 0

  • chainguardvirt-chroot-fips-1.6

    < 0

  • chainguardvirt-chroot-fips-1.7

    < 0

  • chainguardvirt-chroot-fips-1.8

    < 0

  • chainguardvirt-controller-1.6

    < 0

  • chainguardvirt-controller-1.7

    < 0

  • chainguardvirt-controller-1.8

    < 0

  • chainguardvirt-controller-fips-1.7

    < 0

  • chainguardvirt-controller-fips-1.8

    < 0

  • chainguardvirt-handler-1.6

    < 0

  • chainguardvirt-handler-1.7

    < 0

  • chainguardvirt-handler-1.8

    < 0

  • chainguardvirt-handler-fips-1.6

    < 0

  • chainguardvirt-handler-fips-1.7

    < 0

  • chainguardvirt-handler-fips-1.8

    < 0

  • chainguardvirt-launcher-1.7

    all

  • chainguardvirt-launcher-1.7-virt-freezer

    all

  • chainguardvirt-launcher-1.7-virt-launcher-monitor

    all

  • chainguardvirt-launcher-1.7-virt-probe

    all

  • chainguardvirt-launcher-1.7-virt-tail

    all

  • chainguardvirt-launcher-1.8

    all

  • chainguardvirt-launcher-1.8-libvirt-hook-client

    all

  • chainguardvirt-launcher-1.8-virt-freezer

    all

  • chainguardvirt-launcher-1.8-virt-launcher-monitor

    all

  • chainguardvirt-launcher-1.8-virt-probe

    all

  • chainguardvirt-launcher-1.8-virt-tail

    all

  • chainguardvirt-operator-1.6

    all

  • chainguardvirt-operator-1.7

    < 0

  • chainguardvirt-operator-1.8

    < 0

  • chainguardvirt-operator-fips-1.7

    < 0

  • chainguardvirt-operator-fips-1.8

    < 0

  • wolfidocker-machine-driver-harvester

    all

  • kubevirt.iokubevirt

    all | ≤ 1.9.0-beta.0

References (12)