CVE 8.1 HIGH

Tenant-controlled comma smuggles arbitrary CIFS mount options_CVE-2026-41013

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells.

Affected versions:
smb-volume-release: All versions prior to v3.60.0
CF Deployment: All versions prior to v56.0.0

Basic Information

ID CVE-2026-41013
Source vmware
Published Jun 1, 2026 at 17:36
Modified Jun 1, 2026 at 19:40

Affected Product

Vendor CloudFoundry Foundation
Product smb-volume-release
Affected Versions CloudFoundry Foundation smb-volume-release 0
CloudFoundry Foundation CF Deployment 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.