CVE-2026-12080

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.
Configurations

No configuration.

History

20 Jul 2026, 14:16

Type Values Removed Values Added
References
  • () https://gitlab.com/qemu-project/qemu/-/work_items/3929 -

20 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 13:16

Updated : 2026-07-21 18:31


NVD link : CVE-2026-12080

Mitre link : CVE-2026-12080

CVE.ORG link : CVE-2026-12080


JSON object : View

Products Affected

No product.

CWE
CWE-61

UNIX Symbolic Link (Symlink) Following