CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Bulletin ID: 2026-099-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 11:45 AM PDT

The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) driver that lets Kubernetes workloads use Amazon EFS file systems. We identified CVE-2026-85781, an issue in the driver's volume-deletion logic. When the controller is configured with the non-default --delete-access-point-root-dir=true option, it did not verify that the EFS access point referenced by a PersistentVolume's volume handle belonged to the file system referenced by that same volume handle. An authenticated Kubernetes user with permission to create PersistentVolumes could use a crafted volume handle to cause the controller to recursively delete directories from an Amazon EFS file system that the user was not otherwise authorized to modify. This issue does not affect Amazon EFS itself; Amazon EFS access controls operated as designed.

This issue has been addressed in Amazon EFS CSI Driver version v3.4.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Only customers who use the --delete-access-point-root-dir option are affected.

Customers who cannot upgrade immediately should disable --delete-access-point-root-dir, restrict PersistentVolume-creation RBAC to trusted administrators, scope the controller's IAM role to only the file systems it must manage, and attach explicit EFS resource policies to file systems.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 15, 2026 20:57
Versions
2 recorded
Identity
a8d5aaf30df4eb2936be97327c9f4bb9d1826044

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.