A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-12080 is a critical privilege escalation vulnerability in QEMU Guest Agent's SSH key management handler that allows local unprivileged users to manipulate file ownership through symlink exploits. The vulnerability exists in the guest-ssh-add-authorized-keys command handler, where attackers can either abuse predictable directory symlinks or exploit Time-of-Check to Time-of-Use (TOCTOU) race conditions to gain control of arbitrary root-owned files and directories. This affects any system running QEMU with the guest agent enabled, particularly virtualized environments where guest-to-host privilege escalation could enable lateral movement within infrastructure. The attack requires local access but no special privileges, making it a significant threat in multi-tenant cloud environments and shared hosting scenarios.
While this CVE currently maps to zero Casky.ai skills due to the absence of specific MITRE ATT&CK technique mappings, practitioners can detect related attack patterns by monitoring for suspicious file system activity around SSH key directories (/root/.ssh, authorized_keys files) and system calls indicating symlink operations combined with file ownership changes. Detection would focus on identifying TOCTOU race conditions through rapid successive file access and modification events, unusual symlink creation in system directories, and privilege escalation artifacts where unprivileged processes attempt ownership of root-level resources. Security teams should implement file integrity monitoring and auditd rules tracking SSH configuration modifications, inode changes, and unexpected symlink traversals in critical system paths—attack indicators that Claude's reasoning capabilities could correlate across multiple data sources to identify exploitation attempts in real time.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-12080. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation