Kubernetes Vulnerability Allows Remote File Manipulation
Summary
CERT-Bund has issued a security advisory (WID-SEC-2026-0738) regarding a vulnerability in Kubernetes that allows remote authenticated attackers to manipulate files. The vulnerability affects the Open Source Kubernetes CSI Driver for NFS versions prior to 4.13.1 and has a CVSS Base Score of 6.5.
What changed
CERT-Bund has released a security advisory (WID-SEC-2026-0738) detailing a critical vulnerability in Kubernetes, specifically affecting the Open Source Kubernetes CSI Driver for NFS versions earlier than 4.13.1. The vulnerability, rated with a CVSS Base Score of 6.5, allows a remote, authenticated attacker to manipulate files on affected systems. This advisory applies to Linux and UNIX operating systems where Kubernetes is deployed.
Organizations utilizing the affected Kubernetes CSI Driver for NFS must update to a patched version (4.13.1 or later) to mitigate this risk. Failure to address this vulnerability could lead to unauthorized file manipulation, potentially compromising data integrity and system security. While no specific compliance deadline is mentioned, prompt patching is strongly recommended to prevent exploitation.
What to do next
- Update Open Source Kubernetes CSI Driver for NFS to version 4.13.1 or later.
- Review system configurations for potential exploitation of the vulnerability.
Source document (simplified)
[WID-SEC-2026-0738] Kubernetes: Schwachstelle ermöglicht Manipulation von Dateien CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
Produktbeschreibung
Kubernetes ist ein Werkzeug zur Automatisierung der Bereitstellung, Skalierung und Verwaltung von containerisierten Anwendungen.
Produkte
16.03.2026
- Open Source Kubernetes CSI Driver for NFS <4.13.1
Angriff
Angriff
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Dateien zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.