THREAT OPS › Threat News › [NVD] CVE-2026-9804 (HIGH 7.7) — A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (
[NVD] CVE-2026-9804 (HIGH 7.7) — A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (
CVE-2026-9804 CVSS: 7.7 HIGH Published: 2026-05-28T09:16:49.500
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the
Indicators of compromise
- CVE-2026-9804cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9804