logo

New Kubernetes NFS CSI Vulnerability Enables Unauthorized Directory Deletion and Changes

ID: 6a68294c-9297-5bd5-bc0e-36b59f3ae84f

STIX ID: report--6a68294c-9297-5bd5-bc0e-36b59f3ae84f

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Divya

...
...

A path traversal vulnerability in the Kubernetes CSI Driver for NFS (CVE-2026-3864, CVSS 6.5) allows attackers who can create PersistentVolumes referencing the driver to inject `../` sequences into the `subDir` volume identifier, causing the driver to remove or modify directories outside the intended export on the NFS server. The issue affects all driver versions prior to v4.13.1; remediation is to upgrade to v4.13.1 or newer, restrict PV creation privileges, audit `volumeHandle` values, and review CSI controller logs for suspicious removal of subpaths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.