Securitykubernetes_cveAlphaLab AI score 26/100
Path traversal flaw in Kubernetes SMB driver exposes servers to unintended directory deletion
A path traversal vulnerability (CVE-2026-3865) in the Kubernetes Container Storage Interface (CSI) Driver for SMB could enable attackers to delete unintended directories on SMB servers. The flaw manifests when processing the subDir parameter, where inadequate path sanitization permits directory operations outside intended boundaries. This affects all versions prior to the yet-unreleased patch. Kubernetes clusters utilizing SMB-backed persistent volumes should monitor for security updates.