Junglewise Threat Intelligence

CVE-2026-6437: AWS EFS CSI Driver argument injection in volume handling

CVE-2026-6437 · Severity: high · CVSS 6.5 · Published 2026-04-17

Technologies: Amazon AWS. Vendors: AWS, Amazon, Go.

Executive brief

The AWS EFS CSI Driver allows Kubernetes clusters to manage and use Amazon Elastic File System storage. A security flaw in this driver allows users with specific administrative permissions to inject unauthorized settings when mounting storage volumes. This could lead to unauthorized data access or modification within the file system, potentially compromising sensitive business data stored in the cloud.

Technical details

An argument injection vulnerability (CWE-88) exists in the AWS EFS CSI Driver due to improper neutralization of argument delimiters in the volume handling component. Specifically, the 'volumeHandle' (Access Point ID) and 'mounttargetip' fields are not properly sanitized before being passed to the system mount command. An attacker with Kubernetes 'PersistentVolume' creation privileges can use comma-separated values to inject arbitrary mount options. This allows the attacker to apply unauthorized filesystem settings, potentially leading to a breach of confidentiality or integrity on the mounted EFS volumes. The issue is fixed in version v3.0.1.

Affected products

  • AWS EFS CSI Driver < v3.0.1

Timeline

  • 2026-04-16: patched: Version v3.0.1 released
  • 2026-04-17: disclosed: Initial advisory publication

References

Related threats