{"id":"CVE-2026-12080","title":"A flaw was found in the QEMU Guest Agent (qga)","summary":"A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic dire…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-61"],"published":"2026-07-20","updated":"2026-08-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12080","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-12080","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499603","label":"secalert@redhat.com"},{"url":"https://gitlab.com/qemu-project/qemu/-/work_items/3929","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00181,"epssPercentile":0.06759,"ingestedAt":"2026-08-24T12:02:51.065Z","slug":"CVE-2026-12080","body":"## Overview\n\nA flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}