CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

Bulletin ID: 2026-120-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 08:30 AM PDT

The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options.

Impacted versions: >= v3.1.0 AND <= v3.4.2

This issue has been addressed in Amazon EFS CSI Driver version v3.5.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-120-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
October 02, 2026 17:00
Versions
1 recorded
Identity
f1cddc55d36b7ad183da40deeaa82cb99629e3e5

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.