CVE-2026-7374
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.74%
- CWE
- CWE-59
- Published
- 2026-05-26
- Last modified
- 2026-09-10
Affected products
- Red Hat Red Hat Container Native Virtualization 4.12
- Red Hat Red Hat Container Native Virtualization 4.13
- Red Hat Red Hat Container Native Virtualization 4.14
- Red Hat Red Hat Container Native Virtualization 4.15
- Red Hat Red Hat Container Native Virtualization 4.16
- Red Hat Red Hat Container Native Virtualization 4.17
- Red Hat Red Hat Container Native Virtualization 4.18
- Red Hat Red Hat Container Native Virtualization 4.2
Weakness type
Related vulnerabilities
- CVE-2026-11940 — tarfile extraction filter bypass allows escaping the destination directory
- CVE-2026-63294 — Root RCE via image backup.yaml symlink
- CVE-2026-63293 — Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
- CVE-2026-63125 — Incus vulnerable to root RCE via image backup.yaml symlink
- CVE-2026-57571 — Crawl4AI arbitrary file write via download filename path traversal
- CVE-2026-54352 — Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
- CVE-2026-53476 — Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write
- CVE-2026-19429 — An incomplete patch for CVE-2026-33001 in Jenkins Project Jenkins through LTS 2.555.3 allows an authenticated remote att