Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem.
To remediate this issue, users should upgrade to version v3.4.1.
To remediate this issue, users should upgrade to version v3.4.1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1. | |
| Title | Unverified access point ownership in Amazon EFS CSI Driver | |
| First Time appeared |
Aws
Aws aws-efs-csi-driver |
|
| Weaknesses | CWE-283 | |
| CPEs | cpe:2.3:a:aws:aws-efs-csi-driver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-efs-csi-driver |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-04T19:28:03.833Z
Reserved: 2026-09-04T16:27:45.409Z
Link: CVE-2026-85781
No data.
Status : Received
Published: 2026-09-04T19:17:34.157
Modified: 2026-09-04T20:17:33.030
Link: CVE-2026-85781
No data.
OpenCVE Enrichment
Updated: 2026-09-04T20:45:17Z
Weaknesses