CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver
Cybersecurity Classified by Officially
CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver
Bulletin ID: 2026-120-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 08:30 AM PDT
The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options.
Impacted versions: >= v3.1.0 AND <= v3.4.2
This issue has been addressed in Amazon EFS CSI Driver version v3.5.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-120-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- October 02, 2026 17:00
- Versions
- 1 recorded
- Identity
f1cddc55d36b7ad183da40deeaa82cb99629e3e5