---
id: CVE-2026-1530
title: A flaw was found in fog-kubevirt
summary: >-
  A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker
  to perform a Man-in-the-Middle (MITM) attack due to disabled certificate
  validation. This enables the attacker to intercept and potentially alter
  sensitive com…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
  - CWE-295
published: '2026-02-02'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1530'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:5970'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:5971'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1530'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2433784'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:5970'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5971'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1530'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2433784'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1530.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00264
epssPercentile: 0.18535
ingestedAt: '2026-07-03T18:53:52.144Z'
---

## Overview

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
