← Back to feed
Securitykubernetes_cveAlphaLab AI score 26/100

Path traversal flaw in Kubernetes SMB driver exposes servers to unintended directory deletion

A path traversal vulnerability (CVE-2026-3865) in the Kubernetes Container Storage Interface (CSI) Driver for SMB could enable attackers to delete unintended directories on SMB servers. The flaw manifests when processing the subDir parameter, where inadequate path sanitization permits directory operations outside intended boundaries. This affects all versions prior to the yet-unreleased patch. Kubernetes clusters utilizing SMB-backed persistent volumes should monitor for security updates.

Original source← Back to feed