← Back to browse · API

CVE-2026-7374

Severity
CRITICAL
CVSS
9.9
EPSS
0.00596
Risk score
39.81
CISA KEV
No
PoC
Yes
Published
2026-05-26
Modified
2026-08-16
First seen
2026-08-05
Aliases
EUVD-2026-31824, GHSA-7JCP-V9W4-WJMG
Products
Red Hat:Red Hat Container Native Virtualization 4.12 patch: 1779375376, Red Hat:Red Hat Container Native Virtualization 4.13 patch: 1778999881, Red Hat:Red Hat Container Native Virtualization 4.14 patch: 1779321599, Red Hat:Red Hat Container Native Virtualization 4.15 patch: 1778859977, Red Hat:Red Hat Container Native Virtualization 4.16 patch: 1778861274, Red Hat:Red Hat Container Native Virtualization 4.17 patch: 1779174925, Red Hat:Red Hat Container Native Virtualization 4.18 patch: 1778887155, Red Hat:Red Hat Container Native Virtualization 4.19 patch: 1779289071, Red Hat:Red Hat Container Native Virtualization 4.2 patch: 1779288737, Red Hat:Red Hat Container Native Virtualization 4.20 patch: 1779288737, Red Hat:Red Hat Container Native Virtualization 4.21 patch: 1779420069, linux, redhat, suse
Sources
packetstorm 0840ff269535288964feb8e2|CVE-2026-7374
nvd CVE-2026-7374
euvd EUVD-2026-31824
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-7374

Description

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

References