https://seclists.org/oss-sec/2026/q2/97: [kubernetes] CVE-2026-3865: CSI Driver for SMB path traversal via subDir may delete unintended dictories on the SMB server
Published Apr 10, 2026
·Updated
Affected Software
1 affected component
Kubernetes CSI Driver for SMB (smb.csi.k8s.io)<1.20.1
Frequently Asked Questions
1
What is the severity of CVE-2026-3865?
CVE-2026-3865 has been classified as a high severity vulnerability due to its potential to allow unintended directory deletions on the SMB server.
2
How do I fix CVE-2026-3865?
To fix CVE-2026-3865, ensure you validate and sanitize the subDir parameter used in PersistentVolume references to the SMB CSI driver.
3
Who is affected by CVE-2026-3865?
Users of the Kubernetes CSI Driver for SMB that allow PersistentVolume creations with insufficient subDir validation are affected by CVE-2026-3865.
4
What are the potential impacts of CVE-2026-3865?
CVE-2026-3865 could lead to a malicious user deleting unintended directories on the SMB server, compromising data integrity.
5
When was CVE-2026-3865 published?
CVE-2026-3865 was published on April 10, 2026.