Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells.
Affected versions:
smb-volume-release: All versions prior to v3.60.0
CF Deployment: All versions prior to v56.0.0
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0 | |
| Title | Tenant-controlled comma smuggles arbitrary CIFS mount options | |
| Weaknesses | CWE-88 | |
| References |
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-01T19:40:16.203Z
Reserved: 2026-04-16T02:19:16.427Z
Link: CVE-2026-41013
Updated: 2026-06-01T19:40:04.454Z
Status : Received
Published: 2026-06-01T19:16:39.887
Modified: 2026-06-01T21:16:43.947
Link: CVE-2026-41013
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:30:26Z