2026-120-AWSHigh

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

Published
October 2, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options. Impacted versions: >= v3.1.0 AND Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)