← Retour aux CVEs
CVE-2026-3864
MEDIUM6.5
Description
A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie3/20/2026
Derniere modification3/23/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-22
References
https://github.com/kubernetes/kubernetes/issues/137797(jordan@liggitt.net)
https://groups.google.com/g/kubernetes-security-announce/c/i4ZKN9VLcUE(jordan@liggitt.net)
http://www.openwall.com/lists/oss-security/2026/03/17/1(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.