Description
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.



To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Network Policy Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from incomplete validation of pod identifier uniqueness in the aws-network-policy-agent. Prior to version 1.4.0, the agent allows pod names and namespaces that produce identical identifiers. An attacker who can create pods with engineered names can cause identifier collisions that allow traffic to bypass NetworkPolicy rules on other namespaces. This effectively nullifies network segmentation and permits unauthorized communication to resources that should be isolated.

Affected Systems

The flaw affects Amazon EKS clusters that use Amazon VPC CNI and the network policy agent. AWS:amazon-vpc-cni-k8s and AWS:aws-network-policy-agent versions lower than 1.22.4 and 1.4.0, respectively, are vulnerable. Any authenticated user capable of creating or updating pods can exploit the bug, as the unique identifier check is missing from those releases.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% indicates a low probability of exploitation in the current environment. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been observed. Exploitation requires authenticated access to the Kubernetes API and the ability to create pods; once a collision is achieved, the attacker can inject traffic that bypasses NetworkPolicy scopes, potentially enabling lateral movement or data exfiltration across namespaces.

Generated by OpenCVE AI on September 18, 2026 at 01:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the aws-network-policy-agent to version 1.4.0 or later.
  • Upgrade the Amazon VPC CNI Managed Add‑on to version 1.22.4 or later, which includes the updated policy agent.
  • Restrict authenticated users to only those who truly need pod deployment privileges, applying least‑privilege principles to minimize the risk of colliding pod identifiers.

Generated by OpenCVE AI on September 18, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions. To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).
Title Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
First Time appeared Aws
Aws amazon-vpc-cni-k8s
Aws aws-network-policy-agent
Weaknesses CWE-1289
CPEs cpe:2.3:a:aws:amazon-vpc-cni-k8s:*:*:*:*:*:*:*:*
cpe:2.3:a:aws:aws-network-policy-agent:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws amazon-vpc-cni-k8s
Aws aws-network-policy-agent
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Aws Amazon-vpc-cni-k8s Aws-network-policy-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-17T16:08:59.530Z

Reserved: 2026-09-08T14:28:44.391Z

Link: CVE-2026-86831

cve-icon Vulnrichment

Updated: 2026-09-17T16:08:47.266Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:36.980

Modified: 2026-09-17T17:16:51.353

Link: CVE-2026-86831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input