PT-2026-86236 · Amazon · Amazon Efs Csi Driver

CVE-2026-85781

·

Published

2026-09-04

·

Updated

2026-09-08

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon EFS CSI Driver versions prior to v3.4.1
Description The volume deletion component fails to verify the ownership of a storage access point. This allows an authenticated Kubernetes user with PersistentVolume creation privileges to trigger the recursive deletion of directories on an EFS filesystem they are not authorized to access. This is achieved by using a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem.
Recommendations Upgrade to version v3.4.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85781

Affected Products

Amazon Efs Csi Driver