Two path traversal vulnerabilities, CVE-2026-3864 in the Kubernetes NFS CSI driver and CVE-2026-3865 in the SMB CSI driver, allow attackers with persistentvolumes:create permission to escape intended subdirectory boundaries and access other tenants’ data on shared exports. The flaws stem from the drivers trusting attacker-controlled subDir values embedded in PersistentVolume.volumeHandle fields and relying on Go path handling in ways that did not enforce containment, enabling unauthorized read, write, modification, and deletion of files across shared NFS or SMB storage.
Researchers said the issue reflects a broader trust-boundary failure in Kubernetes environments, where requests that are authenticated and authorized by the API are not necessarily safe for privileged components to execute. In some NFS deployments with broader hostPath exposure, the bugs could also lead to arbitrary directory deletion on worker nodes. Fixes were released in NFS CSI Driver v4.13.1 and SMB CSI Driver v1.20.1, while defenders were urged to restrict PersistentVolume creation, tighten RBAC and GitOps service accounts, use admission controls to validate storage parameters, and review similar path-handling patterns across other CSI drivers and cloud-native components.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Patched versions were made available as csi-driver-nfs v4.13.1 and csi-driver-smb v1.20.1 to address the two storage path traversal flaws. Coverage also recommended restricting PersistentVolume creation and adding admission-time validation to reduce similar abuse paths.
Security researchers disclosed CVE-2026-3864 in csi-driver-nfs and CVE-2026-3865 in csi-driver-smb, describing how attacker-controlled subDir values in PersistentVolume volumeHandle fields could bypass intended directory boundaries and enable cross-tenant access to shared storage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcesentinelone.com
Open sourcekubernetes.io
Open sourcekubernetes.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.