Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

A security issue was found in the Amazon EFS CSI Driver, used by Kubernetes clusters with Amazon Elastic File System. Someone with permission to create PersistentVolumes could add extra mount instructions that the system would accept, possibly causing unexpected behavior. Users should upgrade to version 3.5.0 or later and restrict who can create PersistentVolumes to trusted administrators.

QCS published 4/10/2026, 4:48:34 pm ISTVendor disclosure 2/10/2026, 10:08:11 pm ISTVerified 4/10/2026, 4:48:34 pm ISTRevision 1

In plain language

What this advisory means

A security issue was found in the Amazon EFS CSI Driver, used by Kubernetes clusters with Amazon Elastic File System. Someone with permission to create PersistentVolumes could add extra mount instructions that the system would accept, possibly causing unexpected behavior. Users should upgrade to version 3.5.0 or later and restrict who can create PersistentVolumes to trusted administrators.

Technical explanation

How the issue affects the environment

CVE-2026-103505 is a mount option injection vulnerability in the Amazon EFS CSI Driver versions 3.1.0 and above. An attacker with PersistentVolume creation privileges can exploit the mounttargetipmap volumeAttribute by appending comma-separated values within its JSON map entries. The mount utility interprets these appended values as separate mount options, potentially leading to unintended mount configurations. This can affect the security and stability of the system mounting EFS volumes within Kubernetes clusters.

Operational impact

Why teams should care

If exploited, an attacker could influence how file systems are mounted in Kubernetes clusters using Amazon EFS, possibly leading to unauthorized access, privilege escalation, or disruption of workloads that rely on correctly mounted storage. This puts business applications running on affected clusters at risk until the vulnerability is mitigated.

Immediate action

Upgrade the Amazon EFS CSI Driver to version 3.5.0 or later. Also, ensure any derivative or forked code is updated accordingly to include the fix.

Affected and fixed releases

Affected versions>= v3.1.0
Fixed versionsv3.5.0

Temporary risk reduction

Use Kubernetes Role-Based Access Control (RBAC) to restrict PersistentVolume and StorageClass creation privileges to trusted cluster administrators only, preventing untrusted users from injecting arbitrary mount options.

Evidence and validation checklist

  • AWS Security Bulletin 2026-120-AWS published 10/01/2026
  • CVE-2026-103505 description from AWS
  • Version and remediation information from AWS bulletin
  • Kubernetes RBAC recommended as an access control workaround

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source