---
id: CVE-2026-9804
title: A flaw was found in KubeVirt's virt-exportserver component
summary: >-
  A flaw was found in KubeVirt's virt-exportserver component. An attacker with
  specific namespace-level access can exploit a path traversal vulnerability in
  the VMExport directory endpoint. By placing a symbolic link (symlink) within
  an ex…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-59
vendor: Red Hat
product: container-native-virtualization/virt-exportserver-rhel9
affected:
  - container-native-virtualization/virt-exportserver-rhel9 (all versions)
  - container-native-virtualization/virt-exportserver-rhel9 (all versions)
  - container-native-virtualization/virt-exportserver-rhel9 (all versions)
  - container-native-virtualization/virt-exportserver-rhel9 (all versions)
  - container-native-virtualization/virt-exportserver-rhel9 (all versions)
  - container-native-virtualization/virt-exportserver (all versions)
patched:
  - container_native_virtualization 4.17
  - container_native_virtualization 4.18
  - container_native_virtualization 4.19
  - container_native_virtualization 4.20
  - container_native_virtualization 4.21
published: '2026-05-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:35.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9804'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:27903'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27913'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27914'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27983'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28002'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-9804'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482487'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27903'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27913'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27914'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27983'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28002'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-9804'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482487'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9804.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9804'
  - url: >-
      https://github.com/kubevirt/kubevirt/commit/6ea563fa94d8ca803f8dd9394cefd8cae36bb0ee
  - url: 'https://github.com/kubevirt/kubevirt'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-9804'
tags:
  - nvd
  - cve.org
  - osv
  - go
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-30T01:54:32.833433Z'
epss: 0.00516
epssPercentile: 0.42936
aliases:
  - GHSA-mpmf-3w4r-qfpf
  - GO-2026-5883
ecosystem: go
ingestedAt: '2026-07-09T18:56:36.640Z'
---

## Overview

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-9804)

Affected packages:

- `kubevirt.io/kubevirt <= 1.9.0-beta.0`

Source: https://osv.dev/vulnerability/GHSA-mpmf-3w4r-qfpf

## Vendor advisories

- **RHSA-2026:28002** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.17 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28002)
- **RHSA-2026:27913** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.18 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:27913)
- **RHSA-2026:27914** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.19 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:27914)
- **RHSA-2026:27983** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.20 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:27983)
- **RHSA-2026:27903** · Red Hat · fixed in: Red Hat Container Native Virtualization 4.21 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:27903)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Virtualization 4 · no fix planned: Red Hat OpenShift Virtualization 4 · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9804.json)
