CVE-2026-57966

EUVD-2026-40050
A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An attacker could exploit this to write to sensitive locations with the privileges of the spice-vdagent process, typically the logged-in user. This issue requires the SPICE host to be untrusted or compromised for exploitation.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.71%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
spice-spacespice-vdagent
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice-vdagent
bookworm
vulnerable
bookworm (security)
0.22.1-3+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
0.20.0-2+deb11u1
fixed
forky
0.23.0-3
fixed
sid
0.23.0-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spice-vdagent
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
ignored
resolute
deferred