HIGH

CVE-2026-12080

Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys

CVSS v3

7.3

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external manageme

Technical details

CVSS v3 Vector
3.1
Published
7/20/2026
Last Modified
7/20/2026

Frequently asked questions

What is CVE-2026-12080?

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external manageme

Is CVE-2026-12080 actively exploited?

Active exploitation of CVE-2026-12080 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-12080?

CVE-2026-12080 has a CVSS v3 base score of 7.3 (HIGH severity), with vector string 3.1.

Is CVE-2026-12080 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.