PT-2026-93933 · Amazon · Aws-Network-Policy-Agent+1
CVE-2026-86831
·
Published
2026-09-16
·
Updated
2026-09-23
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Amazon EKS Network Policy Agent versions prior to 1.4.0
Description
Improper validation of pod identifier uniqueness allows an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces. This is achieved by using crafted pod and namespace names that result in pod identifier collisions.
Recommendations
Upgrade to Amazon EKS Network Policy Agent 1.4.0 or later.
Upgrade to Amazon VPC CNI Managed Add-on v1.22.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Network-Policy-Agent
Vpc Cni