New Kubernetes NFS CSI Vulnerability Enables Unauthorized Directory Deletion and Changes
ID: 6a68294c-9297-5bd5-bc0e-36b59f3ae84f
STIX ID: report--6a68294c-9297-5bd5-bc0e-36b59f3ae84f
Feed Name: GBHackers
A path traversal vulnerability in the Kubernetes CSI Driver for NFS (CVE-2026-3864, CVSS 6.5) allows attackers who can create PersistentVolumes referencing the driver to inject `../` sequences into the `subDir` volume identifier, causing the driver to remove or modify directories outside the intended export on the NFS server. The issue affects all driver versions prior to v4.13.1; remediation is to upgrade to v4.13.1 or newer, restrict PV creation privileges, audit `volumeHandle` values, and review CSI controller logs for suspicious removal of subpaths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
