Mount Option Injection in Amazon EFS CSI Driver
Medium6.5CVE-2026-103505 · Published Oct 1, 2026 · updated Oct 2, 2026
Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options. Impacted versions: >= v3.1.0 AND <= v3.4.2 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to Medium |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- Severity from
- NVD
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) | Medium5.3 | No fix yet |
| Oct 1 | Uncontrolled recursion in the Ion reader in Amazon Ion Python | High7.5 | No fix yet |
| Oct 1 | Argument injection in AWS security-agent-mcp-server diff scan | High8.2 | No fix yet |
| Sep 29 | GluonTS arbitrary command execution during model deserialization | High7.8 | No fix yet |
| Sep 25 | REMOVE_BASE_PATH strips every leading repetition of the base path, not just one | Low | 1.1.0 |
| Sep 24 | Type confusion in AWS pgcollection allows remote code execution | High8.8 | No fix yet |