{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/qemu-guest-agent/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-12080"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["QEMU Guest Agent"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability","qemu","guest-agent"],"_cs_type":"advisory","_cs_vendors":["QEMU"],"content_html":"\u003cp\u003eA significant local privilege escalation vulnerability, tracked as CVE-2026-12080, has been identified in the QEMU Guest Agent (qga). This flaw allows a local unprivileged user within a QEMU guest operating system to achieve root access. The vulnerability resides within the \u003ccode\u003eguest-ssh-add-authorized-keys\u003c/code\u003e command handler, which can be triggered by an external management layer like libvirt. Attackers can exploit this by manipulating symbolic links, either through a deterministic directory-symlink bypass or by winning a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation enables the attacker to gain ownership of arbitrary root-owned files or directories, thereby escalating their privileges to root within the guest system. The exploit requires the guest-ssh-add-authorized-keys command to be invoked, which is typically done by management tools.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA local unprivileged user first gains access to the QEMU guest operating system.\u003c/li\u003e\n\u003cli\u003eThe user identifies the QEMU Guest Agent (qga) process running with root privileges and recognizes the \u003ccode\u003eguest-ssh-add-authorized-keys\u003c/code\u003e command handler as an exploitable component.\u003c/li\u003e\n\u003cli\u003eThe attacker waits for or orchestrates an external management layer (such as libvirt) to invoke the \u003ccode\u003eguest-ssh-add-authorized-keys\u003c/code\u003e command on the guest agent.\u003c/li\u003e\n\u003cli\u003eConcurrently with the command execution, the attacker creates and manipulates symbolic links within the guest file system, targeting critical root-owned files or directories.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully exploits either a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race within the \u003ccode\u003eguest-ssh-add-authorized-keys\u003c/code\u003e command handler.\u003c/li\u003e\n\u003cli\u003eAs a result of the symlink manipulation, the root-privileged QEMU Guest Agent performs file ownership modifications on the attacker-controlled target (arbitrary root-owned files or directories) instead of the intended SSH authorized_keys file.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the newly gained ownership over these critical root-owned files or directories to achieve full root access within the guest operating system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12080 grants a local unprivileged attacker complete root access within the affected QEMU guest operating system. This allows the attacker to fully compromise the guest, including modifying system configurations, installing malicious software, exfiltrating data, or using the compromised guest as a pivot point for further attacks within the virtualized environment. The integrity and confidentiality of data within the guest OS are severely compromised, and the overall security posture of the virtualized infrastructure is weakened.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-12080 immediately by updating the QEMU Guest Agent to the fixed version provided by your vendor.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for unusual file ownership changes, particularly for root-owned files or directories, which could indicate attempts to exploit CVE-2026-12080.\u003c/li\u003e\n\u003cli\u003eEnsure that management layers interacting with the QEMU Guest Agent are configured with the principle of least privilege and their activities are logged for auditing purposes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T13:21:23Z","date_published":"2026-07-20T13:21:23Z","id":"https://feed.craftedsignal.io/briefs/2026-07-qemu-guest-agent-privesc/","summary":"A local unprivileged user within a QEMU guest can exploit CVE-2026-12080, a vulnerability in the QEMU Guest Agent's 'guest-ssh-add-authorized-keys' command handler, by manipulating symbolic links through a directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race to gain ownership of arbitrary root-owned files or directories, leading to root access within the guest OS.","title":"QEMU Guest Agent Vulnerability Allows Local Privilege Escalation (CVE-2026-12080)","url":"https://feed.craftedsignal.io/briefs/2026-07-qemu-guest-agent-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - QEMU Guest Agent","version":"https://jsonfeed.org/version/1.1"}