7.7
CVE-2026-17527
- EPSS 0.38%
- Veröffentlicht 27.07.2026 10:16:37
- Zuletzt bearbeitet 21.09.2026 15:17:28
- Erkennungen
Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.14
Default Statusaffected
Version
1788157795
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.16
Default Statusaffected
Version
1787585647
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.18
Default Statusaffected
Version
1787586357
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.19
Default Statusaffected
Version
1787234290
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.20
Default Statusaffected
Version
1787231995
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.21
Default Statusaffected
Version
1787235286
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Container Native Virtualization 4.22
Default Statusaffected
Version
1787295217
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Virtualization 4
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.302 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://access.redhat.com/security/cve/CVE-2026-17527
https://bugzilla.redhat.com/show_bug.cgi?id=2507413
https://access.redhat.com/errata/RHSA-2026:59062
https://access.redhat.com/errata/RHSA-2026:59083
https://access.redhat.com/errata/RHSA-2026:59109
https://access.redhat.com/errata/RHSA-2026:60301
https://access.redhat.com/errata/RHSA-2026:60117
https://access.redhat.com/errata/RHSA-2026:61666
https://access.redhat.com/errata/RHSA-2026:62599