Changeflow GovPing Data Privacy & Cybersecurity Kubernetes Vulnerability Allows Remote File Man...
Priority review Notice Added Final

Kubernetes Vulnerability Allows Remote File Manipulation

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 16th, 2026
Detected March 17th, 2026
Email

Summary

CERT-Bund has issued a security advisory (WID-SEC-2026-0738) regarding a vulnerability in Kubernetes that allows remote authenticated attackers to manipulate files. The vulnerability affects the Open Source Kubernetes CSI Driver for NFS versions prior to 4.13.1 and has a CVSS Base Score of 6.5.

What changed

CERT-Bund has released a security advisory (WID-SEC-2026-0738) detailing a critical vulnerability in Kubernetes, specifically affecting the Open Source Kubernetes CSI Driver for NFS versions earlier than 4.13.1. The vulnerability, rated with a CVSS Base Score of 6.5, allows a remote, authenticated attacker to manipulate files on affected systems. This advisory applies to Linux and UNIX operating systems where Kubernetes is deployed.

Organizations utilizing the affected Kubernetes CSI Driver for NFS must update to a patched version (4.13.1 or later) to mitigate this risk. Failure to address this vulnerability could lead to unauthorized file manipulation, potentially compromising data integrity and system security. While no specific compliance deadline is mentioned, prompt patching is strongly recommended to prevent exploitation.

What to do next

  1. Update Open Source Kubernetes CSI Driver for NFS to version 4.13.1 or later.
  2. Review system configurations for potential exploitation of the vulnerability.

Source document (simplified)

[WID-SEC-2026-0738] Kubernetes: Schwachstelle ermöglicht Manipulation von Dateien CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX

Produktbeschreibung

Kubernetes ist ein Werkzeug zur Automatisierung der Bereitstellung, Skalierung und Verwaltung von containerisierten Anwendungen.

Produkte

16.03.2026
- Open Source Kubernetes CSI Driver for NFS <4.13.1

Angriff

Angriff

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Dateien zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 16th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
de

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Containerization

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.