Junglewise Threat Intelligence

CVE-2025-14459: KubeVirt CDI unauthorized PVC cloning in DataImportCron

CVE-2025-14459 · Severity: high · CVSS 8.5 · Published 2026-01-26

Vendors: KubeVirt, Red Hat.

Executive brief

A security flaw in KubeVirt Containerized Data Importer (CDI) allows unauthorized users to copy virtual machine storage volumes from other users' projects. This component is used to import and manage disk images for virtual machines in Kubernetes environments. An exploit could lead to the theft of sensitive data stored on virtual disks by bypassing standard security boundaries between different organizational departments or users.

Technical details

An authorization bypass vulnerability (CWE-639) exists in the KubeVirt Containerized Data Importer (CDI) virt-cdi-controller. The root cause is insufficient validation in the DataImportCron PVC source mechanism, which allows a user to specify a source PVC from a namespace they do not have permissions to access. By creating a DataImportCron in their own namespace and pointing it to a PVC in a target namespace, an authenticated attacker can clone and subsequently access the data within that volume. This vulnerability has been addressed in Red Hat OpenShift Virtualization 4.19.17 (specifically version v4.19.17-5 of the affected components).

Affected products

  • KubeVirt KubeVirt Containerized Data Importer (CDI)
  • Red Hat OpenShift Virtualization 4.19 prior to 4.19.17-5

Timeline

  • 2025-12-10: other: Initial bug report in Red Hat Bugzilla
  • 2026-01-22: patched: Red Hat released security advisory RHSA-2026:0950
  • 2026-01-26: disclosed: Public disclosure of CVE-2025-14459

References

Related threats