THREAT OPS › Threat News › [NVD] CVE-2026-17527 (HIGH 7.7) — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as suf
[NVD] CVE-2026-17527 (HIGH 7.7) — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as suf
CVE-2026-17527 CVSS: 7.7 HIGH Published: 2026-07-27T10:16:37.617
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC t
Indicators of compromise
- CVE-2026-17527cve
- cdi.kubevirt.iodomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17527