A path traversal vulnerability in the Kubernetes CSI Driver for NFS (nfs.csi.k8s.io) could allow attackers with permission to create PersistentVolume objects to supply crafted volumeHandle values containing ../ sequences in the subDir field. During deletion or cleanup operations, the driver may traverse outside the intended managed path and delete or modify unintended directories on the backing NFS server. The issue is tracked as CVE-2026-3864 and carries a CVSS 6.5 rating, with impact focused on integrity and availability rather than confidentiality.
Affected deployments are those running CSI Driver for NFS versions prior to v4.13.1 while allowing non-administrative or otherwise untrusted users to create PersistentVolumes that reference the NFS CSI driver. Kubernetes guidance says organizations should upgrade to v4.13.1 or later, restrict PersistentVolume creation to trusted administrators, inspect volumeHandle values for traversal strings such as ../, and review controller logs for unexpected directory operations such as references to paths escaping the intended export directory. This is a substantive vulnerability disclosure, not promotional or generic content.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A Kubernetes product advisory was published documenting CVE-2026-3864, a path traversal issue in the CSI Driver for NFS. The advisory formalized the disclosure and identified the risk of unintended directory deletion on NFS servers.
Kubernetes maintainers Andy Zhang and Rita Zhang released a fix for CVE-2026-3864 in CSI Driver for NFS version 4.13.1. The vulnerability affects versions prior to v4.13.1 and could allow users able to create PersistentVolumes for nfs.csi.k8s.io to delete or modify unintended directories on the NFS server via ../ traversal sequences.
Shaul Ben Hai of SentinelOne identified a path traversal vulnerability in the Kubernetes CSI Driver for NFS involving insufficient validation of the subDir parameter in volume identifiers. The issue was responsibly disclosed to the Kubernetes project and handled with the Kubernetes Security Response Committee.
Kubernetes maintainers patched a path traversal vulnerability in the SMB CSI driver, tracked as CVE-2026-3865. The flaw was structurally similar to CVE-2026-3864 in the NFS CSI driver and could let an attacker with permission to create PersistentVolume objects manipulate filesystem paths on remote SMB shares.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.