Improper Pod Identifier Uniqueness in Amazon EKS Network Policy Agent
CVE-2026-86831
8.7HIGH
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-86831?
An issue exists in the Amazon EKS Network Policy Agent that allows an authenticated remote user to bypass NetworkPolicy enforcement. This occurs due to insufficient validation of pod identifier uniqueness, where crafted pod and namespace names can lead to identifier collisions affecting co-located pods across different namespaces. To mitigate the risk posed by this vulnerability, it is advised to upgrade to Amazon EKS Network Policy Agent version 1.4.0 or later, as well as the Amazon VPC CNI Managed Add-on to version 1.22.4 or later.
Affected Version(s)
amazon-vpc-cni-k8s 1.14.0 < 1.22.4
aws-network-policy-agent 0 < 1.4.0
