SB2026042078 - Mount option injection in Amazon EFS CSI driver



SB2026042078 - Mount option injection in Amazon EFS CSI driver

Published: April 20, 2026

Security Bulletin ID SB2026042078
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2026-6437)

The vulnerability allows a remote user to modify mount behavior by injecting arbitrary mount options.

The vulnerability exists due to improper input validation in the volumeHandle and mounttargetip fields when processing PersistentVolume definitions and volume attributes. A remote privileged user can append comma-separated values to these fields to modify mount behavior by injecting arbitrary mount options.

Exploitation requires PersistentVolume creation privileges.


Remediation

Install update from vendor's website.