Description
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute.



To remediate this issue, users should upgrade to version v3.5.0 or later.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized alteration of EFS mount options
Action: Immediate upgrade
AI Analysis

Impact

Improper neutralization of argument delimiters in the volume handling component of AWS EFS CSI Driver allows authenticated users who can create PersistentVolumes to inject arbitrary mount options via the comma‑separated mounttargetipmap attribute. This flaw can lead to unauthorized changes to EFS mount behavior, potentially enabling a malicious user to mount EFS volumes with unexpected options that could expose sensitive data, bypass security controls, or disrupt storage access.

Affected Systems

AWS EFS CSI Driver – v3.1.0 through v3.4.2 – is affected. The component resides in the volume handling logic used by Kubernetes clusters that integrate with AWS EFS. Users deploying the driver in these versions are at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Because the exploit requires authenticated users with PersistentVolume creation permissions, the attack vector is remote, authenticated, with limited scope to cluster administrators. EPSS is not available, but the vulnerability is not listed in CISA KEV. The impact is limited to mount option manipulation; however, privileged users could leverage this to bypass storage safeguards or cause denial of service within the cluster.

Generated by OpenCVE AI on October 1, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AWS EFS CSI Driver to v3.5.0 or later.
  • Restrict PersistentVolume creation permissions to trusted users only, ensuring that only authorized personnel can create volumes.
  • Audit existing PersistentVolumes for unsafe mounttargetipmap values and either remove or correct them.
  • Monitor audit logs for suspicious PV creation activity to detect potential exploitation attempts.

Generated by OpenCVE AI on October 1, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Aws
Aws aws-efs-csi-driver
Vendors & Products Aws
Aws aws-efs-csi-driver

Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. To remediate this issue, users should upgrade to version v3.5.0 or later.
Title AWS EFS CSI Driver Mount Option Injection via mounttargetipmap
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Aws Aws-efs-csi-driver
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-01T16:02:04.918Z

Reserved: 2026-09-30T17:35:44.736Z

Link: CVE-2026-103505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:36.627

Modified: 2026-10-01T17:17:18.667

Link: CVE-2026-103505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')