CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Efs Csi ยท 2026-09-09
Actions
Technical Details
| Affected Versions | <=3.4.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-85781 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update Amazon EFS CSI Driver to version v3.4.1 to address CVE-2026-85781, ensuring the driver verifies EFS access point ownership before deletion operations.
For Platform Teams
Deploy the updated Amazon EFS CSI Driver v3.4.1 to enhance security and prevent unauthorized deletions in Amazon EFS file systems.
For Executives
Implement the security patch for Amazon EFS CSI Driver to mitigate risk of unauthorized deletion of directories in Amazon EFS file systems, ensuring data integrity and security.