A vulnerability described as very critical has been identified in Red Hat QEMU. This affects the function
guest-ssh-add-authorized-keys of the component Command Handler. Executing a manipulation can lead to time-of-check time-of-use.
This vulnerability is tracked as CVE-2026-12080. The attack can be launched remotely. No exploit exists.