Description
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
Published: 2026-05-26
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Update cluster RBAC to not allow exec into virt-launcher pods.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 03:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:container_native_virtualization:4.19::el9
References

Wed, 27 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Virtualization
Vendors & Products Redhat openshift Virtualization

Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:container_native_virtualization:4.21::el9

Wed, 27 May 2026 06:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:container_native_virtualization:4 cpe:/a:redhat:container_native_virtualization:4.12::el8
cpe:/a:redhat:container_native_virtualization:4.13::el9
cpe:/a:redhat:container_native_virtualization:4.14::el9
cpe:/a:redhat:container_native_virtualization:4.15::el9
cpe:/a:redhat:container_native_virtualization:4.16::el9
cpe:/a:redhat:container_native_virtualization:4.17::el9
cpe:/a:redhat:container_native_virtualization:4.18::el9
cpe:/a:redhat:container_native_virtualization:4.20::el9
References

Wed, 27 May 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
Title Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
First Time appeared Redhat
Redhat container Native Virtualization
Weaknesses CWE-59
CPEs cpe:/a:redhat:container_native_virtualization:4
Vendors & Products Redhat
Redhat container Native Virtualization
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Container Native Virtualization Openshift Virtualization
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-15T18:55:34.630Z

Reserved: 2026-04-29T06:46:44.106Z

Link: CVE-2026-7374

cve-icon Vulnrichment

Updated: 2026-05-26T13:37:38.502Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-26T14:16:40.717

Modified: 2026-06-17T11:02:18.493

Link: CVE-2026-7374

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-26T12:30:00Z

Links: CVE-2026-7374 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T09:30:26Z

Weaknesses