to scripts. This works for real hardware because in the end it's up to
the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file
mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the
user that created fakefish, power them on and off, and mount arbitrary CD
images to them.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them. | |
| Title | KubeVirt backend is not authenticated | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: redhat-cnalr
Published:
Updated: 2026-08-17T16:00:15.115Z
Reserved: 2026-08-07T12:08:03.283Z
Link: CVE-2026-71566
No data.
Status : Received
Published: 2026-08-17T15:16:57.610
Modified: 2026-08-17T16:17:44.493
Link: CVE-2026-71566
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:45:03Z
-
CWE-306
Missing Authentication for Critical Function