PT-2026-25942 · Kubernetes · Kubernetes-Csi-Driver-Nfs

Shaul Ben Hai

·

Publicado

2026-03-17

·

Atualizado

2026-03-27

·

CVE-2026-3864

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kubernetes CSI Driver for NFS (affected versions not specified)
Description A flaw exists in the Kubernetes CSI Driver for NFS related to insufficient validation of the subDir parameter within volume identifiers. An attacker capable of creating PersistentVolumes utilizing the NFS CSI driver can construct volume identifiers containing path traversal sequences (../). This manipulation could allow the driver to operate on directories outside the intended managed path during volume deletion or cleanup, potentially leading to unauthorized deletion or modification of directories on the NFS server. The vulnerable parameter is subDir.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3864
GHSA-2MJQ-54QG-7W6J
GO-2026-4816
SUSE-SU-2026:1135-1

Produtos afetados

Kubernetes-Csi-Driver-Nfs