CVE-2026-3864 identifies a path traversal vulnerability in the Kubernetes CSI Driver for NFS, stemming from insufficient validation of the subDir parameter in volume identifiers. This medium-severity flaw (CVSS 6.5) allows attackers with high privileges, specifically the ability to create PersistentVolumes, to craft malicious volume identifiers. Exploitation could lead to the deletion or modification of unintended directories on the NFS server during volume deletion or cleanup operations. There is currently no evidence of active exploitation, no public exploit code available, and minimal community or media attention surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kubernetes | CSI Driver For NFS | >= 0, < 4.13.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NFS CSI driver for Kubernetes is Vulnerable to Path Traversal through Volume Identifier Parameter
Mar 21, 2026CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server
CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server
CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server