216.73.216.233

CVE-2026-41013

· Published 01/06/2026 19:16 · Modified 02/06/2026 14:01

Labels: CVE-2026-41013 2026-06-01CVE-2026-41013CWE-88[email protected]

Essential information

Published
01/06/2026 19:16
Modified
02/06/2026 14:01
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cloudfoundry / smb-volume-release cpe:2.3:a:cloudfoundry:smb-volume-release:<3.60.0:*:*:*:*:*:*:*
cloudfoundry / cf deployment cpe:2.3:a:cloudfoundry:cf_deployment:<56.0.0:*:*:*:*:*:*:*

References