๐Ÿ” CVE Alert

CVE-2026-41013

HIGH 8.1

Tenant-controlled comma smuggles arbitrary CIFS mount options

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
10th

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0

CWE CWE-88
Vendor cloudfoundry foundation
Product smb-volume-release
Published Jun 1, 2026
Last Updated Jun 4, 2026
Stay Ahead of the Next One

Get instant alerts for cloudfoundry foundation smb-volume-release

Be the first to know when new high vulnerabilities affecting cloudfoundry foundation smb-volume-release are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CloudFoundry Foundation / smb-volume-release
0 < 3.60.0
CloudFoundry Foundation / CF Deployment
0 < 56.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cloudfoundry.org: https://www.cloudfoundry.org/blog/cve-2026-41013-tenant-controlled-comma-smuggles-arbitrary-cifs-mount-options/