Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-17527
Red Hat Red Hat Container Native Virtualization 4.14 — Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C H N N 7.7 .0057 45.0 —
AFFECTED
Product Versions Fixed
Red Hat Container Native Virtualization 4.14 unspecified 1788157795
Red Hat Container Native Virtualization 4.16 unspecified 1787585647
Red Hat Container Native Virtualization 4.18 unspecified 1787586357
Red Hat Container Native Virtualization 4.19 unspecified 1787234290
Red Hat Container Native Virtualization 4.20 unspecified 1787231995
Red Hat Container Native Virtualization 4.21 unspecified 1787235286
Red Hat Container Native Virtualization 4.22 unspecified 1787295217
Red Hat OpenShift Virtualization 4 unspecified —
TIMELINE
Jul 27 Reserved by redhat
Jul 27 Published (CNA: redhat)
Aug 25 PATCH SHIPPED — CVE-2026-17527 (Red Hat Container Native Virtualization 4.19). Fixed in Red Hat Container Native Virtualization 4.19 1787234290.
Description
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 27, 2026 | Reserved | Reserved by redhat |
| July 27, 2026 | Published | Published (CNA: redhat) |
| August 25, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-17527 (Red Hat Container Native Virtualization 4.19). Fixed in Red Hat Container Native Virtualization 4.19 1787234290. |
Affected
Affected products and packages — 8 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Container Native Virtualization 4.14 | — | — | 1788157795 |
| Red Hat | Red Hat Container Native Virtualization 4.16 | — | — | 1787585647 |
| Red Hat | Red Hat Container Native Virtualization 4.18 | — | — | 1787586357 |
| Red Hat | Red Hat Container Native Virtualization 4.19 | — | — | 1787234290 |
| Red Hat | Red Hat Container Native Virtualization 4.20 | — | — | 1787231995 |
| Red Hat | Red Hat Container Native Virtualization 4.21 | — | — | 1787235286 |
| Red Hat | Red Hat Container Native Virtualization 4.22 | — | — | 1787295217 |
| Red Hat | Red Hat OpenShift Virtualization 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-17527 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.