CVE detail
CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 13
- within the 30d window
- Peak daily
- 13
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:53826access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53797access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53728access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53721access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHEA-2026:53670access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53838access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53763access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53684access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53671access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53655access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:51031access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2494142bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/security/cve/CVE-2026-13622access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-17604CVSS 4.9 · Medium
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data…
- CVE-2026-15056CVSS 6.5 · Medium
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and i…
- CVE-2026-14524CVSS 9.1 · Critical
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all ve…
- CVE-2026-74764CVSS 10.0 · Critical
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names dir…
- CVE-2026-18855CVSS 9.1 · Critical
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to…
- CVE-2026-14484CVSS 9.1 · Critical
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjax…