Skip to content
AWSAWS-2026-120

Mount Option Injection in Amazon EFS CSI Driver

Medium6.5CVE-2026-103505 · Published Oct 1, 2026 · updated Oct 2, 2026

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options. Impacted versions: >= v3.1.0 AND <= v3.4.2 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Oct 2Severity: Unrated to Medium
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Severity from
NVD

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.