CVE-2026-13325
Red Hat Red Hat OpenShift Virtualization 4, kubevirt, openshift virtualization
A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. This listener proxies directly into the target virt-launcher's virtqemud control socket. An attacker with a running pod on the cluster network can connect to this listener and issue unfiltered libvirt RPC commands against another tenant's virtual machine, including reading VM memory and configu...
- CVSS
- 8.5
- EPSS
- 0.18% 7.27% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.26