Skip to content
AWSAWS-2026-016

Mount Option Injection in Amazon EFS CSI Driver

UnratedCVE-2026-6437 · Published Apr 17, 2026 · updated Sep 25, 2026

Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT   Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions:  EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT   Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions:  EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-016-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-6437 - Mount Option Injection in Amazon EFS CSI Driver Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT   Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions:  EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veter

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues
UnratedApr 29
Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS
UnratedApr 27
Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912
UnratedApr 24
Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
UnratedApr 20
Out-of-bounds Write in Firecracker virtio-pci Transport
UnratedApr 7
Issues with AWS Research and Engineering Studio (RES)
UnratedApr 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.