Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT Description: The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) driver that lets Kubernetes workloads use Amazon EFS file systems. We identified CVE-2026-85781, an issue in the driver's volume-deletion logic. When the controller is configured with the non-default --delete-access-point-root-dir=true option, it did not verify that the EFS access point referenced by a PersistentVolume's volume handle belonged to the file system refere...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
b09e0ff13ff8ff967352c1785320e1b8
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.