Description
A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This allows authenticated users with specific custom roles to gain unauthorized access to subresources, potentially disclosing sensitive information or performing actions they are not permitted to do. Additionally, legitimate users may be denied access to resources.
Published: 2026-04-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized subresource access due to improper RBAC evaluation
Action: Assess Impact
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j6cv-3w8p-vrg8 KubeVirt's authorization mechanism improperly truncates subresource names
History

Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Virtualization
Vendors & Products Redhat openshift Virtualization

Thu, 16 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 15 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This allows authenticated users with specific custom roles to gain unauthorized access to subresources, potentially disclosing sensitive information or performing actions they are not permitted to do. Additionally, legitimate users may be denied access to resources.
Title Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
First Time appeared Redhat
Redhat container Native Virtualization
Weaknesses CWE-863
CPEs cpe:/a:redhat:container_native_virtualization:4
Vendors & Products Redhat
Redhat container Native Virtualization
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Container Native Virtualization Openshift Virtualization
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-04-15T18:40:31.052Z

Reserved: 2026-04-15T18:03:12.839Z

Link: CVE-2026-6383

cve-icon Vulnrichment

Updated: 2026-04-15T18:40:25.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-15T19:16:38.520

Modified: 2026-04-17T15:08:01.337

Link: CVE-2026-6383

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-15T18:03:18Z

Links: CVE-2026-6383 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T09:12:30Z

Weaknesses