CVE-2026-3864
Last modified
CVE-2026-3864 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Kubernetes | CSI Driver for NFS | < 4.13.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-3864?
How severe is CVE-2026-3864?
How do I fix CVE-2026-3864?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-38587An Insecure Direct Object Reference (IDOR) vulnerability was…4.3
- CVE-2026-3861LINE client for iOS versions prior to 26.3.0 contains a vuln…7.1
- CVE-2026-38615DedeCMS V5.7.118 is vulnerable to Command Execution in file_…9.8
- CVE-2026-3862Cross-site Scripting (XSS) allows an attacker to submit spec…4.8
- CVE-2026-38637An issue in the pthread_rwlockattr_setpshared() function of …7.5
- CVE-2026-38639An issue in the parse_month function (/time/strptime.rs) of …7.5
- CVE-2026-38640A reachable unwrap in the __assert_fail function (/assert/mo…7.5
- CVE-2026-38641An issue in the DSO::mmap_and_copy function of relibc commit…7.5
- CVE-2026-38651Authentication Bypass vulnerability exists in Netmaker versi…8.2
- CVE-2026-38669wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when …6.1
- CVE-2026-3867An improper ownership management vulnerability has been iden…6
- CVE-2026-3868An improper handling of the length parameter inconsistency v…8.7
Are you affected by CVE-2026-3864?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
