Executive brief
A security flaw in the KubeVirt Containerized Data Importer (CDI) allows users with limited, read-only access to copy sensitive data they should not be able to see. By exploiting an overly permissive configuration, an attacker with basic access to one part of the system can clone virtual machine disks or data volumes from anywhere in the cluster into their own controlled area. This bypasses standard security boundaries designed to keep different projects or departments isolated from one another.
Technical details
A vulnerability exists in the KubeVirt containerized-data-importer (CDI) where the 'cdi.kubevirt.io:view' ClusterRole, intended for read-only access, includes 'create' permissions for the 'datavolumes/source' subresource. CDI's authorization logic incorrectly treats this subresource permission as sufficient to authorize cloning any PersistentVolumeClaim (PVC) in the cluster, even if the user lacks access to the source namespace. An attacker with this 'view' role and 'edit' or 'admin' privileges in any single namespace can exfiltrate data from any PVC in the cluster by cloning it into their own namespace. This represents an authorization bypass (CWE-639) that violates namespace isolation.
Affected products
- Red Hat Red Hat OpenShift Virtualization 4 4
- KubeVirt containerized-data-importer (CDI)
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory