Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If the `guest-ssh-add-authorized-keys` command is not required, it can be disabled by adding it to the qemu-guest-agent block list (qemu-ga --block-rpcs). This prevents the vulnerable code path from being reached while preserving all other guest-agent functionality.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 20 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path. |
| Title | qemu-kvm: qemu-guest-agent: Local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia Redhat openshift |
|
| CPEs | cpe:/a:redhat:enterprise_linux_nvidia: cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia Redhat openshift |
|
| References |
|
Mon, 13 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qemu
Qemu qemu |
|
| Vendors & Products |
Qemu
Qemu qemu |
Mon, 13 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | qemu-kvm: qemu-guest-agent: Local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-20T19:08:22.324Z
Reserved: 2026-06-12T12:44:56.002Z
Link: CVE-2026-12080
Updated: 2026-07-20T18:03:38.950Z
No data.
OpenCVE Enrichment
Updated: 2026-07-21T21:00:13Z