THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-17527 (HIGH 7.7) — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as suf

[NVD] CVE-2026-17527 (HIGH 7.7) — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as suf

lownvdPublished 2026-07-27

CVE-2026-17527 CVSS: 7.7 HIGH Published: 2026-07-27T10:16:37.617

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17527