CVE-2026-3864
A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.81%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-3864",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3864",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-23T14:13:44.147797Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "jordan@liggitt.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "jordan@liggitt.net",
"affectedData": [
{
"vendor": "Kubernetes",
"product": "CSI Driver for NFS",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.13.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.13.1"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-20T23:16:48.303",
"references": [
{
"url": "https://github.com/kubernetes/kubernetes/issues/137797",
"source": "jordan@liggitt.net"
},
{
"url": "https://groups.google.com/g/kubernetes-security-announce/c/i4ZKN9VLcUE",
"source": "jordan@liggitt.net"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/03/17/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "jordan@liggitt.net",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server."
},
{
"lang": "es",
"value": "Se descubrió una vulnerabilidad en el controlador CSI de Kubernetes para NFS donde el parámetro subDir en los identificadores de volumen no se validaba suficientemente. Atacantes con la capacidad de crear PersistentVolumes que hacen referencia al controlador CSI de NFS podrían crear identificadores de volumen que contienen secuencias de salto de ruta (../). Durante las operaciones de eliminación o limpieza de volumen, el controlador podría operar en directorios no deseados fuera de la ruta gestionada prevista dentro de la exportación NFS. Esto podría llevar a la eliminación o modificación de directorios en el servidor NFS."
}
],
"lastModified": "2026-06-17T10:44:21.283",
"sourceIdentifier": "jordan@liggitt.net"
}