Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
UnratedCVE-2026-86831 · Published Sep 16, 2026
Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names and namespace names. This ambiguity can produce identical identifiers for pods across different namespaces, potentially allowing NetworkPolicy enforcement to be bypassed. Impacted versions: - 1.14.0<1.22.3 Amazon VPC CNI Managed Add-on - < v1.4.0 Network Policy Agent Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python | Unrated | No fix yet |
| Sep 14 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM... | Unrated | No fix yet |
| Sep 11 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration | Unrated | No fix yet |
| Sep 11 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | Unrated | No fix yet |
| Sep 11 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | Unrated | No fix yet |
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |