AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63623

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in libvirt allows newly created volume images to be temporarily world-readable during storage volume clone or convert operations due to the `qemu-img` utility's overly permissive file creation settings. This flaw could lead to sensitive information disclosure from guest virtual machines, impacting the confidentiality of data. Organizations utilizing libvirt for virtualization should prioritize addressing this issue to mitigate potential data leaks.

CVE
CVE-2026-63623
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.