CVE-2026-3865: [kubernetes] CVE-2026-3865: CSI Driver for SMB path traversal via subDir may delete unintended dictories on the SMB server
Published Apr 11, 2026
·Updated
Affected Software
1 affected component
Kubernetes CSI Driver for SMB (csi-driver-smb)
Frequently Asked Questions
1
What is the severity of CVE-2026-3865?
The severity of CVE-2026-3865 is classified as high due to the potential for unintended deletions on the SMB server.
2
How do I fix CVE-2026-3865?
To fix CVE-2026-3865, upgrade the Kubernetes CSI Driver for SMB to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2026-3865?
The impact of CVE-2026-3865 includes the risk of deleting unintended directories on the SMB server through a path traversal exploit.
4
Who is affected by CVE-2026-3865?
Any user implementing the Kubernetes CSI Driver for SMB that allows subDir configurations is potentially affected by CVE-2026-3865.
5
When was CVE-2026-3865 published?
CVE-2026-3865 was published on April 11, 2026.