CVE-2026-3864Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-17); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-17: 4Mentions · 2026-03-21: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-17: 3Technical Details · 2026-03-21: 1Technical Details · 2026-03-25: 103-1703-2103-25
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-174
Disclosure2General2
2026-03-211
Disclosure1
2026-03-251
Disclosure1
Full discourse6 posts
  • Kubernetes@kubernetesio
    General

    CVE-2026-3864: CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server - https://github.com/kubernetes/kubernetes/issues/137797

    Post summary

    The tweet reports CVE‑2026‑3864, a path‑traversal flaw in Kubernetes CSI NFS driver that could enable unintended directory deletion. No PoC, exploit code, active exploitation, or remediation information is provided.

    05147148.0K
    320.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3864: Kubernetes: CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server https://www.openwall.com/lists/oss-security/2026/03/17/1

    Post summary

    The snippet announces CVE-2026-3864, a path traversal flaw in the Kubernetes CSI NFS driver that may delete unintended directories, with no PoC, exploit, patch, or active exploitation details provided.

    020126751
    4.4K followersView on X
  • K8sContributors@K8sContributors
    Disclosure

    CVE-2026-3864: CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server - https://github.com/kubernetes/kubernetes/issues/137797

    Post summary

    The text announces CVE‑2026‑3864, a path traversal flaw in the Kubernetes CSI NFS driver that can delete directories, and links to the relevant GitHub issue.

    01020493
    16.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Kubernetes CSI Driver for NFS の脆弱性 CVE-2026-3864 が FIX:パス・トラバーサルによる不正操作 https://iototsecnews.jp/2026/03/17/kubernetes-csi-driver-for-nfs-vulnerability-lets-attackers-delete-or-modify-nfs-server-directories/ 訳者後書:Kubernetes の NFS CSI ドライバーにおける脆弱性 CVE-2026-3864 について解説する記事です。 この問題の原因は、 ボリューム識別子に含まれる subDir パラメータの検証が不十分だったことにあります。 本来は指定された範囲内のディレクトリのみを操作すべきところ、 ” ../” のようなパス・トラバーサル記号を適切に排除できていませんでした。 そのため、 悪意の設定を持つ PersistentVolume が作成されると、 ドライバーが削除やクリーンアップを行う際に、 管理対象外のディレクトリまで操作対象に含まれてしまう危険があります。ご利用のチームは、ご注意ください。 #CSIDriver #CVE20263864 #Kubernetes #Vulnerability

    Post summary

    The article discloses CVE‑2026‑3864, a path‑traversal vulnerability in the Kubernetes NFS CSI driver that could enable malicious PersistentVolumes to delete or modify directories beyond the intended scope.

    01000116
    481 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3864 A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ab… https://www.cve.org/CVERecord?id=CVE-2026-3864

    Post summary

    CVE-2026-3864 reveals a validation flaw in the Kubernetes CSI NFS driver’s subDir parameter, but the post lacks exploitation, patch, or PoC details.

    00000151
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3864 [kubernetes] CVE-2026-3864 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3864

    Post summary

    The post merely references CVE‑2026‑3864 with a link to vulnerability details, providing no additional context or technical information.

    0000043
    4.0K followersView on X

Explore more