CVE-2026-85781
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H
- EPSS probability
- 0.26%
- CWE
- CWE-283
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- aws aws-efs-csi-driver
Weakness type
Related vulnerabilities
- CVE-2026-84386 — A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7,...
- CVE-2026-9745 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-54467 — On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on...
- CVE-2026-15599 — Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
- CVE-2026-44707 — Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
- CVE-2026-44562 — Open WebUI: Model Import Overwrites Any Model Without Ownership Check
- CVE-2026-40337 — Sentry kernel has incomplete ownership check for IRQ line manipulation
- CVE-2026-4269 — Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit