PT-2026-93933 · Amazon · Aws-Network-Policy-Agent+1

CVE-2026-86831

·

Published

2026-09-16

·

Updated

2026-09-23

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Amazon EKS Network Policy Agent versions prior to 1.4.0
Description Improper validation of pod identifier uniqueness allows an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces. This is achieved by using crafted pod and namespace names that result in pod identifier collisions.
Recommendations Upgrade to Amazon EKS Network Policy Agent 1.4.0 or later. Upgrade to Amazon VPC CNI Managed Add-on v1.22.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86831
GHSA-7XV7-8R3J-3J25
GHSA-GJC7-C7MX-X8F3

Affected Products

Aws-Network-Policy-Agent
Vpc Cni