Gbhackers
Kubernetes NFS CSI Driver Vulnerability Allows Unauthorized Directory Access
Article Content
A path traversal vulnerability has been discovered in the Kubernetes Container Storage Interface (CSI) Driver for NFS, allowing attackers to delete or modify unintended directories on NFS servers. This flaw, tracked as CVE-2026-3864, is due to insufficient validation of the subDir parameter in volume identifiers. It affects all versions of the NFS CSI driver and poses a medium-severity risk with a CVSS v3.1 score of 6.5. The vulnerability impacts clusters that allow users to create PersistentVolumes referencing the NFS CSI driver. Organizations using this driver are at risk of unauthorized directory modifications and deletions. The vulnerability was disclosed by SentinelOne researcher Shaul Ben Hai. No active exploitation has been reported yet, but the potential for abuse remains significant. Users are advised to monitor for updates and apply patches as they become available.
Key Points: • CVE-2026-3864 allows unauthorized modifications to NFS server directories. • The vulnerability affects all versions of the Kubernetes NFS CSI driver. • No active exploitation has been reported, but the risk remains significant.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.