bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-6437

show all
Thursday, August 20, 2026

Amazon EFS CSI Driver Vulnerability Allows Mount Option Injection

Amazon EFS CSI Driver versions ≤3.0.0 have a critical vulnerability (CVE-2026-6437) where users with PersistentVolume creation privileges can inject arbitrary mount options through unsanitized Access Point ID and mounttargetip fields. This could let attackers manipulate how volumes mount in your Kubernetes clusters. Update to the latest driver version immediately if you're running affected versions—no AWS services are directly impacted, but your cluster security depends on this patch.

source: [aws/security-bulletin]