PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103505 AWS CVE debrief

AWS EFS CSI Driver Mount Option Injection via mounttargetipmap allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. Users should upgrade to version v3.5.0 or later. This issue arises from improper neutralization of argument delimiters in the volume handling component of AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2. The vulnerability can be exploited via comma-separated values in the mounttargetipmap volumeAttribute. To address this issue, defenders should verify exposure, restrict PersistentVolume creation permissions, and upgrade to v3.5.0 or later.

Vendor
AWS
Product
aws-efs-csi-driver
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-01
Original CVE updated
2026-10-09
Advisory published
2026-10-01
Advisory updated
2026-10-09

Who should care

Kubernetes administrators; AWS users with PersistentVolume creation permissions; Security teams monitoring volume handling components; operators managing affected product deployments; platform administrators; vulnerability management teams; security teams responsible for reviewing and implementing mitigations.

Why it matters

CVE-2026-103505 allows remote authenticated users to inject arbitrary mount options in AWS EFS CSI Driver. Defenders should verify exposure, restrict PersistentVolume creation permissions, and upgrade to v3.5.0 or later.

  • Potential unauthorized data access
  • Possible privilege escalation via injected mount options
  • Required verification of PersistentVolume creation permissions
  • Need for timely upgrade to v3.5.0 or later

Technical summary

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. This issue can be addressed by upgrading to version v3.5.0 or later and verifying PersistentVolume creation permissions. Defenders should also monitor the volume handling component for suspicious activity.

Defensive priority

Upgrade to v3.5.0 or later; verify PersistentVolume creation permissions; monitor volume handling component

Recommended defensive actions

  • Upgrade to aws-efs-csi-driver version v3.5.0 or later
  • Verify and restrict PersistentVolume creation permissions
  • Monitor volume handling component for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

CVE Program record; NVD vulnerability detail; source item; patch; vendor-advisory; third-party-advisory. The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. The source item and patch references offer additional context on the affected product and potential mitigations. Vendor and third-party advisories also provide guidance on addressing this issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103505 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103505

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103505 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103505

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AWS EFS CSI Driver Mount Option Injection via mounttargetipmap

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103505.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.5.0

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-120-aws/

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kubernetes-sigs/aws-efs-csi-driver/security/advisories/GHSA-pv26-6q9q-5773

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.