Improper Neutralization in AWS EFS CSI Driver Allows User Manipulation
CVE-2026-103505

6.9MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
1 October 2026

What is CVE-2026-103505?

The AWS EFS CSI Driver features a vulnerability in the volume handling component, specifically versions v3.1.0 through v3.4.2. This issue arises due to improper neutralization of argument delimiters, enabling remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options through comma-separated values in the mounttargetipmap volumeAttribute. For protection against this vulnerability, users should upgrade to version v3.5.0 or later.

Affected Version(s)

aws-efs-csi-driver 3.1.0 <= 3.4.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.