SB2026042078 - Mount option injection in Amazon EFS CSI driver
Published: April 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2026-6437)
The vulnerability allows a remote user to modify mount behavior by injecting arbitrary mount options.
The vulnerability exists due to improper input validation in the volumeHandle and mounttargetip fields when processing PersistentVolume definitions and volume attributes. A remote privileged user can append comma-separated values to these fields to modify mount behavior by injecting arbitrary mount options.
Exploitation requires PersistentVolume creation privileges.
Remediation
Install update from vendor's website.