PT-2026-86236 · Amazon · Amazon Efs Csi Driver
CVE-2026-85781
·
Published
2026-09-04
·
Updated
2026-09-08
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon EFS CSI Driver versions prior to v3.4.1
Description
The volume deletion component fails to verify the ownership of a storage access point. This allows an authenticated Kubernetes user with PersistentVolume creation privileges to trigger the recursive deletion of directories on an EFS filesystem they are not authorized to access. This is achieved by using a crafted PersistentVolume
volumeHandle that pairs an access point from one filesystem with a different target filesystem.Recommendations
Upgrade to version v3.4.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Efs Csi Driver