Improper Pod Identifier Uniqueness in Amazon EKS Network Policy Agent
CVE-2026-86831

8.7HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
16 September 2026

What is CVE-2026-86831?

An issue exists in the Amazon EKS Network Policy Agent that allows an authenticated remote user to bypass NetworkPolicy enforcement. This occurs due to insufficient validation of pod identifier uniqueness, where crafted pod and namespace names can lead to identifier collisions affecting co-located pods across different namespaces. To mitigate the risk posed by this vulnerability, it is advised to upgrade to Amazon EKS Network Policy Agent version 1.4.0 or later, as well as the Amazon VPC CNI Managed Add-on to version 1.22.4 or later.

Affected Version(s)

amazon-vpc-cni-k8s 1.14.0 < 1.22.4

aws-network-policy-agent 0 < 1.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.