PatchSiren cyber security CVE debrief
CVE-2026-103505 AWS CVE debrief
AWS EFS CSI Driver Mount Option Injection via mounttargetipmap allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. Users should upgrade to version v3.5.0 or later. This issue arises from improper neutralization of argument delimiters in the volume handling component of AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2. The vulnerability can be exploited via comma-separated values in the mounttargetipmap volumeAttribute. To address this issue, defenders should verify exposure, restrict PersistentVolume creation permissions, and upgrade to v3.5.0 or later.
- Vendor
- AWS
- Product
- aws-efs-csi-driver
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-09
Who should care
Kubernetes administrators; AWS users with PersistentVolume creation permissions; Security teams monitoring volume handling components; operators managing affected product deployments; platform administrators; vulnerability management teams; security teams responsible for reviewing and implementing mitigations.
Why it matters
CVE-2026-103505 allows remote authenticated users to inject arbitrary mount options in AWS EFS CSI Driver. Defenders should verify exposure, restrict PersistentVolume creation permissions, and upgrade to v3.5.0 or later.
- Potential unauthorized data access
- Possible privilege escalation via injected mount options
- Required verification of PersistentVolume creation permissions
- Need for timely upgrade to v3.5.0 or later
Technical summary
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. This issue can be addressed by upgrading to version v3.5.0 or later and verifying PersistentVolume creation permissions. Defenders should also monitor the volume handling component for suspicious activity.
Defensive priority
Upgrade to v3.5.0 or later; verify PersistentVolume creation permissions; monitor volume handling component
Recommended defensive actions
- Upgrade to aws-efs-csi-driver version v3.5.0 or later
- Verify and restrict PersistentVolume creation permissions
- Monitor volume handling component for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
CVE Program record; NVD vulnerability detail; source item; patch; vendor-advisory; third-party-advisory. The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. The source item and patch references offer additional context on the affected product and potential mitigations. Vendor and third-party advisories also provide guidance on addressing this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103505 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103505
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103505 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103505
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AWS EFS CSI Driver Mount Option Injection via mounttargetipmap
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103505.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.5.0
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-120-aws/
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/kubernetes-sigs/aws-efs-csi-driver/security/advisories/GHSA-pv26-6q9q-5773
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.